3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-12092
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-58337
Akuvox Smart Doorphone Web
8.7
HIGH
EPSS
0.0%
2024 CWE-862 1 PoC

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.

CVE-2024-12089
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
0.8%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-12090
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-3594
IDonate Web Windows
8.7
HIGH
EPSS
1.0%
2024 1 PoC

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-22917
Software Genérico Web Database
8.6
HIGH
EPSS
1.1%
2024 1 PoC

SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

CVE-2024-43357
ecma262 Web
8.6
HIGH
EPSS
0.6%
2024 CWE-248 5 PoCs

ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 spec refactor, may lead to mis-implementation in a way that could present as a security vulnerability, such as type confusion and pointer dereference. The internal async generator machinery calls regular promise resolver functions on IteratorResult (`{ done, value }`) objects that it creates, assuming that the IteratorResult objects will not be then-ables. Unfortunately, these IteratorResult objects inherit from `Obj

CVE-2024-20353
🔥 KEV Cisco Adaptive Security Appliance (ASA) Software Web Networking
8.6
HIGH
EPSS
19.5%
2024 CWE-835 2 PoCs

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

CVE-2024-36416
SuiteCRM Web
8.6
HIGH
EPSS
44.7%
2024 CWE-779 1 PoC

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

CVE-2024-58313
xbtitFM Web
8.6
HIGH
EPSS
0.1%
2024 CWE-434 1 PoC

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

CVE-2024-0368
Hustle – Email Marketing, Lead Generation, Optins, Popups Web Windows
8.6
HIGH
EPSS
1.6%
2024 CWE-522 2 PoCs

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.

CVE-2024-21549
spatie/browsershot Web
8.6
HIGH
EPSS
0.0%
2024 CWE-20 2 PoCs

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).

CVE-2024-48766
NetAlertX Web ⚡ nuclei
8.6
HIGH
EPSS
77.7%
2024 CWE-698 1 PoC

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

CVE-2024-1061
Software Genérico Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
83.4%
2024 CWE-89 1 PoC

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

CVE-2024-37818
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2024 1 PoC

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request. NOTE: The Strapi Development Community argues that this issue is not valid. They contend that "the strapi/admin was wrongly attributed a flaw that only pertains to the strapi.io website, and which, at the end of the day, does not pose any real SSRF risk to applications that make use of the Strapi library."

CVE-2024-21136
Retail Xstore Office Web Database ⚡ nuclei
8.6
HIGH
EPSS
42.1%
2024 0 PoCs

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xsto

CVE-2024-58295
ElkArte Forum Web
8.6
HIGH
EPSS
0.6%
2024 CWE-434 1 PoC

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.

CVE-2024-58282
Serendipity Web
8.6
HIGH
EPSS
0.3%
2024 CWE-434 1 PoC

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server.

CVE-2024-37359
Pentaho Data Integration & Analytics Web Networking
8.6
HIGH
EPSS
0.0%
2024 CWE-918 1 PoC

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not validate the Host header of incoming HTTP/HTTPS requests.   By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the atta

CVE-2024-34470
Software Genérico Web ⚡ nuclei
8.6
HIGH
EPSS
93.6%
2024 5 PoCs

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.