6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-55591
🔥 KEV FortiOS General ⚡ nuclei
9.6
CRITICAL
EPSS
94.1%
2024 CWE-288 11 PoCs

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVE-2024-1244
OSSEC-HIDS Agent Windows
9.5
CRITICAL
EPSS
1.0%
2024 CWE-73 1 PoC

Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.

CVE-2024-13503
NTC2218, NTC2250, NTC2299 General
9.5
CRITICAL
EPSS
0.5%
2024 CWE-120 1 PoC

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary modules) allows Local Execution of Code, Remote Code Inclusion. This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The issue is both present on the PowerPC versions of the modem and the ARM versions. A stack buffer buffer overflow in the swdownload binary allows attackers to execute arbitrary code. The parse_INFO function uses an unrestricted `sscanf` to read a string of an

CVE-2024-1243
Wazuh Agent Windows
9.5
CRITICAL
EPSS
1.2%
2024 CWE-73 1 PoC

Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.

CVE-2024-53677
Apache Struts Web
9.5
CRITICAL
EPSS
93.1%
2024 20 PoCs

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in  h

CVE-2024-42466
upKeeper Manager General
9.5
CRITICAL
EPSS
0.4%
2024 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-0917
paddlepaddle/paddle General
9.4
CRITICAL
EPSS
1.8%
2024 CWE-94 1 PoC

remote code execution in paddlepaddle/paddle 2.6.0

CVE-2024-6235
NetScaler Console General ⚡ nuclei
9.4
CRITICAL
EPSS
86.8%
2024 0 PoCs

Sensitive information disclosure in NetScaler Console

CVE-2024-35307
Pandora FMS General
9.4
CRITICAL
EPSS
15.3%
2024 CWE-88 1 PoC

Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.

CVE-2024-34226
Software Genérico Web Database
9.4
CRITICAL
EPSS
0.4%
2024 1 PoC

SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.

CVE-2024-1874
PHP Web Windows
9.4
CRITICAL
EPSS
63.4%
2024 CWE-116 3 PoCs

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVE-2024-46636
Software Genérico Database
9.4
CRITICAL
EPSS
0.0%
2024 1 PoC

NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter

CVE-2024-47062
navidrome Database ⚡ nuclei
9.4
CRITICAL
EPSS
84.7%
2024 CWE-89 1 PoC

Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furthermore, the names of the parameters are not properly escaped, leading to SQL Injections. Finally, the username is used in a `LIKE` statement, allowing people to log in with `%` instead of their username. When adding parameters to the URL, they are automatically included in an SQL `LIKE` statement (depending on the parameter's name). This allo

CVE-2024-28253
OpenMetadata General ⚡ nuclei
9.4
CRITICAL
EPSS
92.9%
2024 CWE-94 0 PoCs

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()` which, in turn, gets called from `EntityResource.createOrUpdate()`. Note that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated. In order to reach

CVE-2024-36439
Software Genérico General
9.4
CRITICAL
EPSS
0.6%
2024 4 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.

CVE-2024-1624
Documentation server Web
9.4
CRITICAL
EPSS
0.4%
2024 CWE-78 1 PoC

An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA Composer from Release R2023 through Release R2024. A specially crafted HTTP request can lead to arbitrary command execution.

CVE-2024-9264
Grafana DevOps Database ⚡ nuclei
9.4
CRITICAL
EPSS
94.0%
2024 CWE-94 13 PoCs

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

CVE-2024-25124
fiber General
9.4
CRITICAL
EPSS
0.5%
2024 CWE-346 2 PoCs

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard (`*`) while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. The impact of this misconfiguration is high as it can lead to unauthorized access to sensitive user data and expose the system to various types of attacks listed in the PortSwig

CVE-2024-37802
Software Genérico Database
9.4
CRITICAL
EPSS
0.1%
2024 1 PoC

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.

CVE-2024-8963
🔥 KEV CSA (Cloud Services Appliance) Cloud ⚡ nuclei
9.4
CRITICAL
EPSS
94.2%
2024 CWE-22 1 PoC

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.