3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-24105
Software Genérico Web Database
7.8
HIGH
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.

CVE-2024-0091
GPU display driver, vGPU software, and Cloud Gaming Web Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-822 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVE-2024-24520
Software Genérico Web
7.8
HIGH
EPSS
0.2%
2024 3 PoCs

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

CVE-2024-24890
gala-gopher Web
7.8
HIGH
EPSS
0.1%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/extends/ebpf.Probe/src/ioprobe/ioprobe.C. This issue affects gala-gopher: through 1.0.2.

CVE-2024-23762
Software Genérico Web
7.8
HIGH
EPSS
0.0%
2024 1 PoC

Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

CVE-2024-27718
Software Genérico Web Database ⚡ nuclei
7.8
HIGH
EPSS
6.3%
2024 0 PoCs

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

CVE-2024-31484
CPC80 Central Processing/Communication Web
7.8
HIGH
EPSS
0.1%
2024 CWE-170 2 PoCs

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Ethernet Interface IEC60870-5-104 (All versions < V10.46), ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 (All versions < V03.27), PCCX26 Ax 1703 PE, Contr, Communication Element (All versions < V06.05). The affected devices contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the con

CVE-2024-34332
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2024 1 PoC

An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent to the Kernel Driver using the DeviceIoControl Windows API.

CVE-2024-26507
Software Genérico Web
7.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

CVE-2024-43779
ClearML Web
7.7
HIGH
EPSS
0.3%
2024 CWE-200 2 PoCs

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2024-12015
WP Project Manager Web Database Windows
7.7
HIGH
EPSS
0.3%
2024 CWE-89 1 PoC

The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

CVE-2024-43687
TimeProvider 4100 Web
7.7
HIGH
EPSS
3.4%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-33452
Software Genérico Web
7.7
HIGH
EPSS
1.3%
2024 1 PoC

An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

CVE-2024-6379
3DSwymer Web
7.7
HIGH
EPSS
1.0%
2024 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-31210
wordpress-develop Web Windows
7.7
HIGH
EPSS
1.0%
2024 CWE-434 1 PoC

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, th

CVE-2024-5585
PHP Web Windows
7.7
HIGH
EPSS
0.9%
2024 CWE-116 1 PoC

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVE-2024-28434
Software Genérico Web
7.6
HIGH
EPSS
0.2%
2024 1 PoC

The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.

CVE-2024-28320
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2024 2 PoCs

Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.

CVE-2024-35540
Software Genérico Web
7.6
HIGH
EPSS
8.7%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2024-42346
galaxy Web
7.6
HIGH
EPSS
10.3%
2024 CWE-79 1 PoC

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches. Users are advised to upgrade. There are no known workarounds for this vulnerability.