3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-7766
Adicon Server Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-21083
BI Publisher (formerly XML Publisher) Web Database
7.2
HIGH
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-20404
Cisco Unified Contact Center Enterprise Web Networking ⚡ nuclei
7.2
HIGH
EPSS
81.1%
2024 CWE-918 1 PoC

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.

CVE-2024-27177
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
7.2
HIGH
EPSS
5.9%
2024 CWE-22 2 PoCs

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-44871
Software Genérico Web
7.2
HIGH
EPSS
19.6%
2024 1 PoC

An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-44916
Software Genérico Web
7.2
HIGH
EPSS
1.3%
2024 1 PoC

Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

CVE-2024-9504
Booking calendar, Appointment Booking System Web Windows
7.2
HIGH
EPSS
0.7%
2024 CWE-434 1 PoC

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2024-38878
Omnivise T3000 Application Server R9.2 Web
7.2
HIGH
EPSS
12.8%
2024 CWE-22 1 PoC

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.

CVE-2024-40101
Software Genérico Web
7.2
HIGH
EPSS
1.1%
2024 1 PoC

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

CVE-2024-11372
Connexion Logs Web Database Windows
7.2
HIGH
EPSS
1.3%
2024 1 PoC

The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-13618
aoa-downloadable Web Windows
7.2
HIGH
EPSS
0.2%
2024 1 PoC

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

CVE-2024-55103
Software Genérico Web Database
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.

CVE-2024-58258
SugarCRM Web
7.2
HIGH
EPSS
2.2%
2024 CWE-94 1 PoC

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

CVE-2024-6753
Social Auto Poster Web Windows ⚡ nuclei
7.2
HIGH
EPSS
5.0%
2024 CWE-79 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-6486
ImageMagick Engine Web Windows
7.2
HIGH
EPSS
3.5%
2024 1 PoC

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

CVE-2024-11269
AHAthat Plugin Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.

CVE-2024-25415
Software Genérico Web
7.2
HIGH
EPSS
7.7%
2024 2 PoCs

A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.

CVE-2024-9022
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
7.2
HIGH
EPSS
1.6%
2024 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-27178
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
7.2
HIGH
EPSS
5.9%
2024 CWE-22 2 PoCs

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-24899
aops-zeus Web
7.2
HIGH
EPSS
0.3%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py. This issue affects aops-zeus: from 1.2.0 through 1.4.0.