6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40502
Software Genérico Database
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx

CVE-2024-43360
zoneminder Database ⚡ nuclei
9.8
CRITICAL
EPSS
63.3%
2024 CWE-89 0 PoCs

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

CVE-2024-51053
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-36080
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

CVE-2024-23741
Software Genérico General
9.8
CRITICAL
EPSS
24.2%
2024 2 PoCs

An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-22902
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

CVE-2024-45252
Halo version 11.7.1.5 General
9.8
CRITICAL
EPSS
0.6%
2024 CWE-78 1 PoC

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-41197
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-28595
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.3%
2024 1 PoC

SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

CVE-2024-51065
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

CVE-2024-57430
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.

CVE-2024-25730
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).

CVE-2024-6924
TrueBooker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.5%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-57061
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

CVE-2024-53544
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.

CVE-2024-41593
Software Genérico General
9.8
CRITICAL
EPSS
7.7%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.

CVE-2024-2054
Artica Proxy Web
9.8
CRITICAL
EPSS
86.9%
2024 CWE-502 3 PoCs

The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.

CVE-2024-32370
Software Genérico Web
9.8
CRITICAL
EPSS
3.5%
2024 1 PoC

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.

CVE-2024-25250
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

CVE-2024-10811
Endpoint Manager General
9.8
CRITICAL
EPSS
4.7%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.