13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-7939
3DSwymer Web
8.7
HIGH
EPSS
0.9%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-12089
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
0.8%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-43684
TimeProvider 4100 Web
8.7
HIGH
EPSS
0.2%
2024 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.

CVE-2024-54449
LogicalDOC Community Web
8.7
HIGH
EPSS
0.2%
2024 CWE-23 1 PoC

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVE-2024-58310
Network Management Card 4 Web
8.7
HIGH
EPSS
0.2%
2024 CWE-22 1 PoC

APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like /etc/passwd by using encoded path traversal characters in HTTP requests.

CVE-2024-58316
online-shopping-system-advanced Web Database
8.7
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.

CVE-2024-43683
TimeProvider 4100 Web
8.7
HIGH
EPSS
0.2%
2024 CWE-601 1 PoC

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.

CVE-2024-8004
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
0.9%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-58312
xbtitFM Web
8.7
HIGH
EPSS
3.3%
2024 CWE-22 1 PoC

xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.

CVE-2024-58283
WBCE CMS Web
8.7
HIGH
EPSS
0.4%
2024 CWE-434 1 PoC

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.

CVE-2024-12091
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-12090
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-35306
Pandora FMS Web
8.7
HIGH
EPSS
0.5%
2024 CWE-78 1 PoC

OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.

CVE-2024-58294
FreePBX Web
8.7
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CVE-2024-58276
Obi08/Enrollment System Web Database
8.7
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.

CVE-2024-52302
Java-springboot-codebase Web
8.7
HIGH
EPSS
4.4%
2024 CWE-434 1 PoC

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).

CVE-2024-58337
Akuvox Smart Doorphone Web
8.7
HIGH
EPSS
0.0%
2024 CWE-862 1 PoC

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.

CVE-2019-25255
VideoFlow Digital Video Protection DVP Web
8.7
HIGH
EPSS
0.1%
2019 CWE-78 3 PoCs

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.

CVE-2019-25647
PhreeBooks ERP Web
8.7
HIGH
EPSS
0.3%
2019 CWE-434 1 PoC

PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse shell connections and execute system commands.

CVE-2019-25333
Momentum Series JAWS Web Cloud
8.7
HIGH
EPSS
0.8%
2019 CWE-22 1 PoC

Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP request paths. Attackers can exploit the vulnerability by sending crafted GET requests with multiple '../' sequences to read sensitive files like /etc/passwd outside the web root directory.