6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-44541
Software Genérico Database
9.8
CRITICAL
EPSS
2.9%
2024 1 PoC

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

CVE-2024-22320
Operational Decision Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
90.8%
2024 CWE-502 1 PoC

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

CVE-2024-35373
Software Genérico Web
9.8
CRITICAL
EPSS
2.2%
2024 1 PoC

Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

CVE-2024-6459
News Element Elementor Blog Magazine Web Windows
9.8
CRITICAL
EPSS
5.8%
2024 1 PoC

The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-21546
unisharp/laravel-filemanager Web
9.8
CRITICAL
EPSS
4.4%
2024 CWE-94 2 PoCs

Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.

CVE-2024-54820
Software Genérico Database
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

CVE-2024-29973
NAS326 firmware Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-78 11 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVE-2024-39705
Software Genérico General
9.8
CRITICAL
EPSS
10.8%
2024 1 PoC

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

CVE-2024-4320
parisneo/lollms-webui Networking
9.8
CRITICAL
EPSS
66.2%
2024 CWE-29 1 PoC

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to improper handling of the `name` parameter in the `ExtensionBuilder().build_extension()` method, which allows for local file inclusion (LFI) leading to arbitrary code execution. An attacker can exploit this vulnerability by crafting a malicious `name` parameter that causes the server to load and execute a `__init__.py` file from an arbitrary location, such as t

CVE-2024-43441
Apache HugeGraph-Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
90.4%
2024 CWE-302 0 PoCs

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

CVE-2024-46946
Software Genérico Networking
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9babcbeb9ff527b0ec0c6 (2023-10-05).

CVE-2024-49328
WP REST API FNS Web
9.8
CRITICAL
EPSS
41.6%
2024 CWE-288 2 PoCs

Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

CVE-2024-50490
PegaPoll General
9.8
CRITICAL
EPSS
52.4%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.

CVE-2024-48126
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

CVE-2024-4358
🔥 KEV Telerik Report Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 CWE-290 7 PoCs

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

CVE-2024-46483
Software Genérico General
9.8
CRITICAL
EPSS
13.9%
2024 1 PoC

Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow with attacker-controlled content.

CVE-2024-4548
DIAEnergie Database
9.8
CRITICAL
EPSS
45.0%
2024 CWE-20 1 PoC

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

CVE-2024-38289
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.3%
2024 0 PoCs

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

CVE-2024-7314
AJ-Report Web ⚡ nuclei
9.8
CRITICAL
EPSS
70.1%
2024 CWE-288 0 PoCs

anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

CVE-2024-6890
Journyx (jtime) General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-321 2 PoCs

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.