6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-54385
Radio Player General ⚡ nuclei
7.2
HIGH
EPSS
81.0%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83.

CVE-2024-40101
Software Genérico Web
7.2
HIGH
EPSS
1.1%
2024 1 PoC

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

CVE-2024-12735
Advance Post Prefix Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks

CVE-2024-0566
Smart Manager Web Database Windows
7.2
HIGH
EPSS
2.5%
2024 2 PoCs

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2024-6451
AI Engine Web Windows
7.2
HIGH
EPSS
0.7%
2024 1 PoC

AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.

CVE-2024-40318
Software Genérico General
7.2
HIGH
EPSS
10.1%
2024 1 PoC

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-9162
All-in-One WP Migration and Backup Web Windows
7.2
HIGH
EPSS
62.6%
2024 CWE-94 1 PoC

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.

CVE-2024-10793
WP Activity Log Web Windows
7.2
HIGH
EPSS
68.7%
2024 CWE-79 3 PoCs

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.

CVE-2024-22274
VMware vCenter Server General
7.2
HIGH
EPSS
63.5%
2024 4 PoCs

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

CVE-2024-20404
Cisco Unified Contact Center Enterprise Web Networking ⚡ nuclei
7.2
HIGH
EPSS
81.1%
2024 CWE-918 1 PoC

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.

CVE-2024-6753
Social Auto Poster Web Windows ⚡ nuclei
7.2
HIGH
EPSS
5.0%
2024 CWE-79 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-24139
Software Genérico Database
7.2
HIGH
EPSS
7.5%
2024 1 PoC

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

CVE-2024-13869
WPvivid — Backup, Migration & Staging Web Windows
7.2
HIGH
EPSS
21.9%
2024 CWE-434 2 PoCs

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents

CVE-2024-50572
RUGGEDCOM RM1224 LTE(4G) EU Networking
7.2
HIGH
EPSS
1.2%
2024 CWE-74 1 PoC

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V8.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V8.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V8.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8

CVE-2024-33529
Software Genérico General
7.2
HIGH
EPSS
0.8%
2024 1 PoC

ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.

CVE-2024-8699
Z-Downloads Web Windows
7.2
HIGH
EPSS
0.9%
2024 1 PoC

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2024-21827
ER7206 Omada Gigabit VPN Router Networking
7.2
HIGH
EPSS
0.2%
2024 CWE-489 2 PoCs

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2024-33250
Software Genérico General
7.2
HIGH
EPSS
0.4%
2024 1 PoC

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

CVE-2024-44916
Software Genérico Web
7.2
HIGH
EPSS
1.3%
2024 1 PoC

Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

CVE-2024-38878
Omnivise T3000 Application Server R9.2 Web
7.2
HIGH
EPSS
12.8%
2024 CWE-22 1 PoC

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.