1919 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-39914
fogproject Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2024 CWE-77 0 PoCs

FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.

CVE-2024-4620
ARForms - Premium WordPress Form Builder Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
72.4%
2024 1 PoC

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

CVE-2024-6220
简数采集器 Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.6%
2024 CWE-434 0 PoCs

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-2879
LayerSlider Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 2 PoCs

The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-8425
WooCommerce Ultimate Gift Card Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
42.7%
2024 CWE-434 2 PoCs

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added.

CVE-2024-11680
🔥 KEV ProjectSend Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-306 1 PoC

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

CVE-2024-24329
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
83.3%
2024 0 PoCs

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

CVE-2024-43360
zoneminder Database ⚡ nuclei
9.8
CRITICAL
EPSS
63.3%
2024 CWE-89 0 PoCs

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

CVE-2024-6924
TrueBooker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.5%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-57049
Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
34.6%
2024 1 PoC

A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. NOTE: this is disputed by the Supplier because the response to the API call is only "non-sensitive UI initialization variables."

CVE-2024-24882
Masteriyo - LMS General ⚡ nuclei
9.8
CRITICAL
EPSS
48.3%
2024 CWE-266 0 PoCs

Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

CVE-2024-29972
NAS326 firmware Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2024 CWE-78 4 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVE-2024-23692
🔥 KEV HTTP File Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 CWE-1336 17 PoCs

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

CVE-2024-44000
LiteSpeed Cache General ⚡ nuclei
9.8
CRITICAL
EPSS
92.8%
2024 CWE-522 6 PoCs

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

CVE-2024-51978
DCP-J928N-W/B Web ⚡ nuclei
9.8
CRITICAL
EPSS
53.6%
2024 CWE-1391 3 PoCs

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

CVE-2024-5276
FileCatalyst Workflow Database ⚡ nuclei
9.8
CRITICAL
EPSS
87.2%
2024 CWE-20 1 PoC

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.

CVE-2024-12209
WP Umbrella: Update Backup Restore & Monitoring Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
89.8%
2024 CWE-98 2 PoCs

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-9643
F3x36 Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
26.2%
2024 CWE-489 1 PoC

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.

CVE-2024-34982
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
80.4%
2024 0 PoCs

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.