6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21090
MySQL Connectors Database
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.3.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2024-36857
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
53.4%
2024 0 PoCs

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

CVE-2024-21077
Trade Management Web Database
7.5
HIGH
EPSS
0.5%
2024 1 PoC

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-32737
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
51.6%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.

CVE-2024-42657
Software Genérico Networking
7.5
HIGH
EPSS
2.1%
2024 2 PoCs

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process

CVE-2024-13496
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
19.3%
2024 CWE-89 1 PoC

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This vulnerability was previously published as being fi

CVE-2024-38819
Spring Framework Web ⚡ nuclei
7.5
HIGH
EPSS
92.1%
2024 CWE-22 5 PoCs

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVE-2024-8176
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 CWE-674 2 PoCs

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

CVE-2024-42651
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.

CVE-2024-31841
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

CVE-2024-21007
WebLogic Server Database
7.5
HIGH
EPSS
0.8%
2024 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-39676
Apache Pinot Web
7.5
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue. Details:  When using a request to path “/appconfigs” to the controller, it can lead to the disclosure of sensitive information such as system information (e.g. arch, os version), environment information (e.g. maxHeapSize) and Pinot configurations (e.g. zookeeper path). This issue was addressed by the Role-based Access Control https://docs.pinot.apache.or

CVE-2024-4436
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2024 CWE-400 1 PoC

The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

CVE-2024-49359
ZimaOS Web
7.5
HIGH
EPSS
0.8%
2024 CWE-552 2 PoCs

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users to list the contents of any directory on the server. By manipulating the path parameter, attackers can access sensitive system directories such as `/etc`, potentially exposing critical configuration files and increasing the risk of further attacks. As of time of publication, no known patched versions are available.

CVE-2024-33700
WBR-6012 Networking
7.5
HIGH
EPSS
0.3%
2024 CWE-20 2 PoCs

The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to cause a denial of service through a series of malformed FTP commands. This can lead to device reboots and service disruption.

CVE-2024-38257
Windows 10 Version 1809 Web Windows
7.5
HIGH
EPSS
4.3%
2024 CWE-908 1 PoC

Microsoft AllJoyn API Information Disclosure Vulnerability

CVE-2024-45248
Multi-DNC General
7.5
HIGH
EPSS
0.3%
2024 CWE-35 1 PoC

Multi-DNC – CWE-35: Path Traversal: '.../...//'

CVE-2024-5882
Ultimate Classified Listings Web Windows
7.5
HIGH
EPSS
2.3%
2024 1 PoC

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVE-2024-46609
Software Genérico Web
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords

CVE-2024-47916
Boa web server 0.94.14rc21 General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')