6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-13888
WPMobile.App Web Windows ⚡ nuclei
7.2
HIGH
EPSS
1.9%
2024 CWE-601 0 PoCs

The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-9698
Crafthemes Demo Import Web Windows
7.2
HIGH
EPSS
46.9%
2024 CWE-434 1 PoC

The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-8190
🔥 KEV CSA (Cloud Services Appliance) Cloud
7.2
HIGH
EPSS
91.4%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

CVE-2024-27130
QTS General
7.2
HIGH
EPSS
81.0%
2024 CWE-120 3 PoCs

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

CVE-2024-34370
EAN for WooCommerce General
7.2
HIGH
EPSS
9.2%
2024 CWE-269 1 PoC

Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

CVE-2024-0795
mintplex-labs/anything-llm General
7.2
HIGH
EPSS
0.6%
2024 CWE-284 1 PoC

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance

CVE-2024-25420
Software Genérico General
7.2
HIGH
EPSS
1.6%
2024 1 PoC

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

CVE-2024-54330
Hurrakify General ⚡ nuclei
7.2
HIGH
EPSS
72.5%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in hurraki Hurrakify hurrakify allows Server Side Request Forgery.This issue affects Hurrakify: from n/a through <= 2.4.

CVE-2024-7014
Telegram for Android General
7.1
HIGH
EPSS
17.5%
2024 CWE-20 2 PoCs

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

CVE-2024-34469
Software Genérico Web
7.1
HIGH
EPSS
1.2%
2024 1 PoC

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

CVE-2024-13891
Schedule Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-40492
Software Genérico General
7.1
HIGH
EPSS
7.7%
2024 1 PoC

Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.

CVE-2024-35428
Software Genérico General
7.1
HIGH
EPSS
0.7%
2024 1 PoC

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.

CVE-2024-26292
Avid NEXIS E-series General
7.1
HIGH
EPSS
0.2%
2024 CWE-22 1 PoC

An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

CVE-2024-29889
glpi Database ⚡ nuclei
7.1
HIGH
EPSS
71.2%
2024 CWE-89 0 PoCs

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.

CVE-2024-47191
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 1 PoC

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

CVE-2024-12400
tourmaster Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2024-13631
Om Stripe Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6529
Ultimate Classified Listings Web Windows
7.1
HIGH
EPSS
52.4%
2024 2 PoCs

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5082
Nexus Repository General ⚡ nuclei
7.1
HIGH
EPSS
6.4%
2024 CWE-94 1 PoC

A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.