3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-46278
Software Genérico Web
8.4
HIGH
EPSS
1.2%
2024 1 PoC

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

CVE-2024-51379
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.

CVE-2024-28143
Scan2Net Web
8.4
HIGH
EPSS
0.1%
2024 CWE-620 2 PoCs

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.

CVE-2024-51380
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.

CVE-2024-51382
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compromise the integrity and security of the system.

CVE-2024-27169
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
8.4
HIGH
EPSS
0.0%
2024 CWE-306 1 PoC

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/models/versions, see the reference URL.

CVE-2024-25858
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.

CVE-2024-51381
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

CVE-2024-41668
cbioportal Web
8.3
HIGH
EPSS
0.1%
2024 CWE-918 1 PoC

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, cBioPortal could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances. A fix has been released in version 6.0.12. As a workaround, one might be able to disable `/proxy` endpoint entirely via, for example, nginx.

CVE-2024-9593
Time Clock Pro Web Windows ⚡ nuclei
8.3
HIGH
EPSS
85.5%
2024 CWE-94 3 PoCs

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.

CVE-2024-4749
wp-eMember Web Windows
8.3
HIGH
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-35219
openapi-generator Web ⚡ nuclei
8.3
HIGH
EPSS
53.2%
2024 CWE-22 0 PoCs

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

CVE-2024-5420
utnserver Pro Web ⚡ nuclei
8.3
HIGH
EPSS
46.6%
2024 CWE-79 6 PoCs

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2024-27971
Premmerce Permalink Manager for WooCommerce Web
8.3
HIGH
EPSS
67.4%
2024 CWE-98 1 PoC

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.

CVE-2024-41637
Software Genérico Web
8.3
HIGH
EPSS
0.3%
2024 1 PoC

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.

CVE-2024-5410
IAP-420 Web
8.3
HIGH
EPSS
1.9%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2024-41671
twisted Web
8.3
HIGH
EPSS
0.1%
2024 CWE-444 1 PoC

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

CVE-2024-35199
serve DevOps Web
8.2
HIGH
EPSS
0.1%
2024 CWE-668 1 PoC

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. Customers using PyTorch inference Deep Learning Containers (DLC) through Amazon SageMaker and EKS are not affected. This issue in TorchServe has been fixed in PR #3083. TorchServe release 0.11.0 includes the fix to address this vulnerability. Users are advised to upgrade. There are no known workarounds

CVE-2024-5736
AdmirorFrames Web
8.2
HIGH
EPSS
28.8%
2024 CWE-918 1 PoC

Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.

CVE-2024-9466
Expedition Web Networking
8.2
HIGH
EPSS
20.1%
2024 CWE-532 2 PoCs

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.