3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-6366
User Profile Builder Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
91.5%
2024 3 PoCs

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

CVE-2024-22393
Apache Answer Web
9.1
CRITICAL
EPSS
26.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

CVE-2024-54879
Software Genérico Web
9.1
CRITICAL
EPSS
4.3%
2024 2 PoCs

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

CVE-2024-25641
cacti Web
9.1
CRITICAL
EPSS
88.1%
2024 CWE-20 7 PoCs

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences a

CVE-2024-26517
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

CVE-2024-5973
MasterStudy LMS WordPress Plugin Web Windows
9.1
CRITICAL
EPSS
0.9%
2024 1 PoC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVE-2024-7385
WP Simple HTML Sitemap Web Database Windows
9.1
CRITICAL
EPSS
13.1%
2024 CWE-89 1 PoC

The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-42914
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.

CVE-2024-36248
Multiple MFPs (multifunction printers) Web Cloud
9.1
CRITICAL
EPSS
0.2%
2024 CWE-798 3 PoCs

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-5450
Bug Library Web Windows
9.1
CRITICAL
EPSS
2.1%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

CVE-2024-40898
Apache HTTP Server Web Windows
9.1
CRITICAL
EPSS
0.7%
2024 CWE-918 4 PoCs

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

CVE-2024-37285
Kibana Web Database
9.1
CRITICAL
EPSS
1.1%
2024 CWE-502 2 PoCs

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv  and Kibana privileges https://www.elastic.co/guide/en/fleet/current/fleet-roles-and-privileges.html  assigned to them. The following Elasticsearch indices permissions are required * write privilege on the system indices .k

CVE-2024-5315
ERP CMS Web Database ⚡ nuclei
9.1
CRITICAL
EPSS
63.0%
2024 CWE-89 0 PoCs

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

CVE-2024-34987
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.0%
2024 2 PoCs

A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.

CVE-2024-51060
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

CVE-2024-51063
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

CVE-2024-57971
KNOWAGE Web
9.1
CRITICAL
EPSS
0.0%
2024 CWE-99 1 PoC

DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.

CVE-2024-29868
Apache StreamPipes Web ⚡ nuclei
9.1
CRITICAL
EPSS
78.4%
2024 CWE-338 1 PoC

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

CVE-2024-56278
WP Ultimate Exporter Web
9.1
CRITICAL
EPSS
49.1%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1.

CVE-2024-36104
Apache OFBiz Web ⚡ nuclei
9.1
CRITICAL
EPSS
93.1%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.