3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-30188
Apache DolphinScheduler Web ⚡ nuclei
8.8
HIGH
EPSS
88.5%
2024 CWE-20 0 PoCs

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue.

CVE-2024-3406
WP Prayer Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-28741
Software Genérico Web
8.8
HIGH
EPSS
88.0%
2024 3 PoCs

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

CVE-2024-33891
Software Genérico Web
8.8
HIGH
EPSS
0.5%
2024 4 PoCs

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.

CVE-2024-32003
wn-dusk-plugin Web
8.8
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User plugin without having to go through authentication. This route is `[[URL]]/_dusk/login/[[USER ID]]/[[MANAGER]]` - where `[[URL]]` is the base URL of the site, `[[USER ID]]` is the ID of the user account and `[[MANAGER]]` is the authentication manager (either `backend` for Backend, or `user` for the User plugin). If a co

CVE-2024-35241
composer Web
8.8
HIGH
EPSS
0.4%
2024 CWE-77 2 PoCs

Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.

CVE-2024-25938
Foxit Reader Web
8.8
HIGH
EPSS
3.5%
2024 CWE-416 2 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2024-5080
wp-eMember Web Windows
8.8
HIGH
EPSS
0.9%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

CVE-2024-22263
Spring Cloud Skipper DevOps Web Cloud
8.8
HIGH
EPSS
77.7%
2024 1 PoC

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

CVE-2024-41226
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2024 3 PoCs

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.

CVE-2024-50858
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.

CVE-2024-45507
Apache OFBiz Web ⚡ nuclei
8.8
HIGH
EPSS
89.5%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVE-2024-6244
PZ Frontend Manager Web Windows
8.8
HIGH
EPSS
12.6%
2024 2 PoCs

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-4535
KKProgressbar2 Free Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-10673
Top Store Web Windows
8.8
HIGH
EPSS
51.9%
2024 CWE-862 1 PoC

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.

CVE-2024-37779
Software Genérico Web
8.8
HIGH
EPSS
4.6%
2024 1 PoC

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

CVE-2024-12594
Login Page Styler – Custom WordPress Login Page Customizer & Security Web Windows
8.8
HIGH
EPSS
3.0%
2024 CWE-862 1 PoC

The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'lps_generate_temp_access_url' AJAX action in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to login as other users such as subscribers.

CVE-2024-5793
Houzez Theme - Functionality Web Database Windows
8.8
HIGH
EPSS
0.7%
2024 CWE-89 1 PoC

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-13146
Booknetic Web Windows
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVE-2024-10629
GPX Viewer Web Windows
8.8
HIGH
EPSS
57.6%
2024 CWE-862 2 PoCs

The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() function in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files on the affected site's server which may make remote code execution possible.