33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-4399
cas General ⚡ nuclei
9.1
CRITICAL
EPSS
25.0%
2024 1 PoC

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

CVE-2024-22120
Zabbix Database
9.1
CRITICAL
EPSS
92.1%
2024 CWE-20 3 PoCs

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CVE-2024-51747
kanboard Database
9.1
CRITICAL
EPSS
1.4%
2024 CWE-22 1 PoC

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, can set arbitrary file links, by abusing path traversals. Once the modified db is uploaded and the project page is accessed, a file download can be triggered and all files, readable in the context of the Kanbo

CVE-2024-48941
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.

CVE-2024-5975
CZ Loan Management Web Database Windows ⚡ nuclei
9.1
CRITICAL
EPSS
43.9%
2024 1 PoC

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-32842
EPM Database
9.1
CRITICAL
EPSS
9.1%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-3673
Web Directory Free Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
92.2%
2024 2 PoCs

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

CVE-2024-32846
EPM Database
9.1
CRITICAL
EPSS
9.1%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-35244
Multiple MFPs (multifunction printers) General
9.1
CRITICAL
EPSS
0.2%
2024 CWE-798 3 PoCs

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-2257
Digisol Router DG-GR1321 Networking
9.1
CRITICAL
EPSS
3.6%
2024 CWE-20 2 PoCs

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.

CVE-2024-32002
git General
9.1
CRITICAL
EPSS
79.6%
2024 CWE-22 62 PoCs

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is dis

CVE-2024-53900
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
52.2%
2024 2 PoCs

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-4180
The Events Calendar Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
42.4%
2024 1 PoC

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

CVE-2024-54507
iOS and iPadOS General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory.

CVE-2024-36104
Apache OFBiz Web ⚡ nuclei
9.1
CRITICAL
EPSS
93.1%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

CVE-2024-11042
invoke-ai/invokeai Web Networking Database
9.1
CRITICAL
EPSS
0.9%
2024 CWE-73 1 PoC

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.

CVE-2024-25170
Software Genérico General
9.1
CRITICAL
EPSS
1.8%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

CVE-2024-0818
paddlepaddle/paddle General
9.1
CRITICAL
EPSS
0.3%
2024 CWE-22 1 PoC

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

CVE-2024-41713
🔥 KEV Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
94.1%
2024 5 PoCs

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVE-2024-38883
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.