6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-27167
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the reference URL.

CVE-2024-6492
Remote Desktop Manager Windows
7.4
HIGH
EPSS
0.6%
2024 1 PoC

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.

CVE-2024-20767
🔥 KEV ColdFusion General ⚡ nuclei
7.4
HIGH
EPSS
94.0%
2024 CWE-284 6 PoCs

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

CVE-2024-27171
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
1.7%
2024 CWE-276 1 PoC

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

CVE-2024-28147
edu-sharing Web
7.4
HIGH
EPSS
0.4%
2024 CWE-434 2 PoCs

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious JavaScript code which will be executed if a user visits the direct URL of the collection preview image (Stored Cross Site Scripting). It is also possible to upload SVG files that include nested XML entities. Those are parsed when a user visits the direct URL of the collection preview image, which may be utilized for a Denial of Service attack. This issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.

CVE-2024-38514
ChatGPT-Next-Web Web ⚡ nuclei
7.4
HIGH
EPSS
70.5%
2024 CWE-918 0 PoCs

NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpoint` GET parameter on the WebDav API endpoint. This SSRF can be used to perform arbitrary HTTPS request from the vulnerable instance (MKCOL, PUT and GET methods supported), or to target NextChat users and make them execute arbitrary JavaScript code in their browser. This vulnerability has been patched in version 2.12.4.

CVE-2024-27149
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2024-44727
Software Genérico Web Database
7.4
HIGH
EPSS
0.3%
2024 1 PoC

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

CVE-2024-27151
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.6%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the reference URL.

CVE-2024-27150
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2024-27152
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2024-21514
opencart/opencart Database
7.4
HIGH
EPSS
60.5%
2024 CWE-89 2 PoCs

This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9. As an anonymous unauthenticated user, if the Divido payment module is installed (it does not have to be enabled), it is possible to exploit SQL injection to gain unauthorised access to the backend database. For any site which is vulnerable, any unauthenticated user could exploit this to dump the entire OpenCart database, including customer PII data.

CVE-2024-33306
Software Genérico Web
7.4
HIGH
EPSS
0.1%
2024 1 PoC

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.

CVE-2024-27147
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2024-31320
Android General
7.4
HIGH
EPSS
0.7%
2024 1 PoC

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-44779
Software Genérico Web
7.4
HIGH
EPSS
2.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVE-2024-44778
Software Genérico Web
7.4
HIGH
EPSS
0.7%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVE-2024-3116
pgAdmin 4 Web
7.4
HIGH
EPSS
90.7%
2024 3 PoCs

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.

CVE-2024-36249
Multiple MFPs (multifunction printers) Web
7.4
HIGH
EPSS
0.2%
2024 CWE-79 1 PoC

Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-44777
Software Genérico Web
7.4
HIGH
EPSS
0.6%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.