38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-48202
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

CVE-2024-10245
Relais 2FA Web Windows
9.8
CRITICAL
EPSS
36.4%
2024 CWE-288 1 PoC

The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This is due to incorrect authentication and capability checking in the 'rl_do_ajax' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVE-2024-29303
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection

CVE-2024-36678
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2024-46256
Software Genérico Web
9.8
CRITICAL
EPSS
60.1%
2024 1 PoC

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

CVE-2024-31666
Software Genérico Web
9.8
CRITICAL
EPSS
27.1%
2024 1 PoC

An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.

CVE-2024-0705
Payment Gateway of Stripe for WooCommerce Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.7%
2024 CWE-89 0 PoCs

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11068
DSL6740C Web Networking
9.8
CRITICAL
EPSS
1.2%
2024 CWE-648 1 PoC

The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

CVE-2024-6809
Simple Video Directory Web Database Windows
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-44812
Software Genérico Web Database
9.8
CRITICAL
EPSS
18.7%
2024 1 PoC

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

CVE-2024-45195
🔥 KEV Apache OFBiz Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-425 1 PoC

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVE-2024-6460
Grow by Tradedoubler Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 3 PoCs

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-7094
JS Help Desk – AI-Powered Support & Ticketing System Web Windows
9.8
CRITICAL
EPSS
72.0%
2024 CWE-94 1 PoC

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and

CVE-2024-45256
Software Genérico Web Database
9.8
CRITICAL
EPSS
50.9%
2024 1 PoC

An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.

CVE-2024-4898
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.1%
2024 CWE-862 3 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.

CVE-2024-26304
Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central Web
9.8
CRITICAL
EPSS
73.2%
2024 2 PoCs

There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2024-11349
AdForest Web Windows
9.8
CRITICAL
EPSS
9.8%
2024 CWE-288 2 PoCs

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.

CVE-2024-3234
gaizhenbiao/chuanhuchatgpt Web ⚡ nuclei
9.8
CRITICAL
EPSS
84.0%
2024 CWE-22 0 PoCs

The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, the outdated version of gradio it employs is susceptible to path traversal, as identified in CVE-2023-51449. This vulnerability allows unauthorized users to bypass the intended restrictions and access sensitive files, such as `config.json`, which contains API keys. The issue affects the latest version of chuanhuchatgpt prior to the fixed version released on 20

CVE-2024-51064
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

CVE-2024-40324
Software Genérico Web
9.8
CRITICAL
EPSS
12.0%
2024 1 PoC

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.