3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-9441
eMerge e3-Series Web
9.8
CRITICAL
EPSS
60.1%
2024 CWE-78 5 PoCs

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

CVE-2024-12252
SEO LAT Auto Post Web Windows
9.8
CRITICAL
EPSS
66.5%
2024 CWE-94 2 PoCs

The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.

CVE-2024-4295
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 CWE-89 3 PoCs

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11635
Iptanus File Upload Web Windows
9.8
CRITICAL
EPSS
23.7%
2024 CWE-94 1 PoC

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

CVE-2024-46532
Software Genérico Web Database
9.8
CRITICAL
EPSS
4.2%
2024 2 PoCs

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

CVE-2024-21534
jsonpath-plus Web
9.8
CRITICAL
EPSS
92.7%
2024 CWE-94 5 PoCs

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVE-2024-23692
🔥 KEV HTTP File Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 CWE-1336 17 PoCs

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

CVE-2024-51051
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.

CVE-2024-46377
Software Genérico Web
9.8
CRITICAL
EPSS
22.1%
2024 1 PoC

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.

CVE-2024-33485
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component

CVE-2024-45410
traefik Web Cloud
9.8
CRITICAL
EPSS
13.9%
2024 CWE-345 1 PoC

Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible to remove or modify these headers. Since the application trusts the value of these headers, security implications might arise, if they can be modified. For HTTP/1.1, however, it was found that some of theses custom headers can indeed be removed and in certain cases manipulated. The attack relies on the HTTP/1.1 behavior

CVE-2024-25414
Software Genérico Web
9.8
CRITICAL
EPSS
2.9%
2024 1 PoC

An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVE-2024-24029
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

CVE-2024-53480
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

CVE-2024-57430
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.

CVE-2024-30985
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

CVE-2024-51053
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-4434
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.1%
2024 CWE-89 1 PoC

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-51065
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

CVE-2024-45489
Software Genérico Web Cloud
9.8
CRITICAL
EPSS
7.9%
2024 2 PoCs

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.