1708 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-54676
Apache OpenMeetings Web
9.8
CRITICAL
EPSS
6.1%
2024 CWE-502 1 PoC

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.

CVE-2024-4883
WhatsUp Gold Web
9.8
CRITICAL
EPSS
92.2%
2024 CWE-77 1 PoC

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

CVE-2024-30982
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

CVE-2024-10508
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Web Windows
9.8
CRITICAL
EPSS
15.3%
2024 CWE-230 3 PoCs

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.

CVE-2024-32640
MasaCMS Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 6 PoCs

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

CVE-2024-13011
WP Foodbakery Web Windows
9.8
CRITICAL
EPSS
2.3%
2024 CWE-434 1 PoC

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-9106
Wechat Social login 微信QQ钉钉登录插件 Web Windows
9.8
CRITICAL
EPSS
41.2%
2024 CWE-288 1 PoC

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

CVE-2024-46532
Software Genérico Web Database
9.8
CRITICAL
EPSS
4.2%
2024 2 PoCs

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

CVE-2024-12155
SV100 Companion Web Windows
9.8
CRITICAL
EPSS
5.6%
2024 CWE-862 1 PoC

The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function in all versions up to, and including, 2.0.02. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. CVE-2024-54229 may be a duplicate of this issue.

CVE-2024-33485
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component

CVE-2024-24029
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

CVE-2024-9932
Wux Blog Editor Web Windows
9.8
CRITICAL
EPSS
75.4%
2024 CWE-434 2 PoCs

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-5488
SEOPress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
71.9%
2024 1 PoC

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

CVE-2024-27143
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
0.2%
2024 CWE-250 2 PoCs

Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts

CVE-2024-52316
Apache Tomcat Web
9.8
CRITICAL
EPSS
2.7%
2024 CWE-391 1 PoC

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The fol

CVE-2024-55507
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

CVE-2024-35374
Software Genérico Web Database
9.8
CRITICAL
EPSS
8.4%
2024 1 PoC

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

CVE-2024-11635
Iptanus File Upload Web Windows
9.8
CRITICAL
EPSS
23.7%
2024 CWE-94 1 PoC

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

CVE-2024-13513
Oliver POS – A WooCommerce Point of Sale (POS) Web Windows
9.8
CRITICAL
EPSS
0.1%
2024 CWE-862 1 PoC

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.

CVE-2024-7954
SPIP Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2024 CWE-95 13 PoCs

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.