38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-12155
SV100 Companion Web Windows
9.8
CRITICAL
EPSS
5.6%
2024 CWE-862 1 PoC

The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function in all versions up to, and including, 2.0.02. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. CVE-2024-54229 may be a duplicate of this issue.

CVE-2021-42013
🔥 KEV Apache HTTP Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 CWE-22 51 PoCs

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

CVE-2024-31819
Software Genérico Web
9.8
CRITICAL
EPSS
83.1%
2024 4 PoCs

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

CVE-2024-55875
http4k Web
9.8
CRITICAL
EPSS
7.2%
2024 CWE-200 1 PoC

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side Request Forgery and even execute code under some circumstances. Version 5.41.0.0 contains a patch for the issue.

CVE-2024-10589
Leopard - WordPress Offload Media Web Windows
9.8
CRITICAL
EPSS
0.4%
2024 CWE-862 1 PoC

The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the import_settings() function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2023-47253
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2023 4 PoCs

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

CVE-2024-10586
Debug Tool Web Windows
9.8
CRITICAL
EPSS
58.9%
2024 CWE-862 2 PoCs

The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution. CVE-2024-52416 may be a duplicate of this issue.

CVE-2024-30990
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.

CVE-2024-6624
JSON API User Web Windows
9.8
CRITICAL
EPSS
43.5%
2024 CWE-269 2 PoCs

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

CVE-2023-41503
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

CVE-2024-4883
WhatsUp Gold Web
9.8
CRITICAL
EPSS
92.2%
2024 CWE-77 1 PoC

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

CVE-2021-4073
RegistrationMagic Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.0%
2021 CWE-287 0 PoCs

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

CVE-2024-8911
LatePoint Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
30.9%
2024 CWE-89 0 PoCs

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note that changing a WordPress user's password is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. Without this setting enabled, only the pass

CVE-2024-44808
Software Genérico Web
9.8
CRITICAL
EPSS
3.4%
2024 1 PoC

An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.

CVE-2024-55099
Software Genérico Web Database
9.8
CRITICAL
EPSS
21.0%
2024 2 PoCs

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVE-2024-5084
Hash Form – Drag & Drop Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2024 CWE-434 7 PoCs

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2023-30805
Net-Gen Application Firewall Web Networking
9.8
CRITICAL
EPSS
14.8%
2023 CWE-78 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

CVE-2023-34409
Software Genérico Web
9.8
CRITICAL
EPSS
2.0%
2023 1 PoC

In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made against unauthenticated API routes, to access otherwise protected API routes leading to escalation of privileges and information disclosure.

CVE-2024-27145
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
0.3%
2024 CWE-22 2 PoCs

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions

CVE-2024-3136
MasterStudy LMS WordPress Plugin – for Online Courses and Education Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
54.2%
2024 CWE-98 1 PoC

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.