6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46636
Software Genérico Database
9.4
CRITICAL
EPSS
0.0%
2024 1 PoC

NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter

CVE-2024-5910
🔥 KEV Expedition Networking ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-306 1 PoC

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

CVE-2024-8752
WebIQ Windows ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-22 1 PoC

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

CVE-2024-55982
Share Buttons – Social Media Database
9.3
CRITICAL
EPSS
31.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.

CVE-2024-50491
RSVP ME Database
9.3
CRITICAL
EPSS
37.7%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

CVE-2024-13979
St. Joe ERP System ("圣乔ERP系统") Web Database ⚡ nuclei
9.3
CRITICAL
EPSS
9.0%
2024 CWE-89 2 PoCs

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundatio

CVE-2024-58307
CSZCMS Web Database
9.3
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

CVE-2024-7395
JetPort 5601v3 General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-287 2 PoCs

An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

CVE-2024-58299
FTP Server General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-121 1 PoC

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

CVE-2024-47073
dataease General ⚡ nuclei
9.3
CRITICAL
EPSS
56.1%
2024 CWE-347 0 PoCs

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-43917
TI WooCommerce Wishlist Database ⚡ nuclei
9.3
CRITICAL
EPSS
90.0%
2024 CWE-89 2 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.

CVE-2024-43144
Cost Calculator Builder Database ⚡ nuclei
9.3
CRITICAL
EPSS
23.2%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVE-2024-57428
Software Genérico Web
9.3
CRITICAL
EPSS
2.0%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.

CVE-2024-42500
HPE HP-UX ONCplus General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

CVE-2024-4879
🔥 KEV Now Platform General ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-1287 12 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-28752
Apache CXF Web ⚡ nuclei
9.3
CRITICAL
EPSS
50.8%
2024 CWE-918 1 PoC

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

CVE-2024-6060
Webscopes Web
9.3
CRITICAL
EPSS
0.1%
2024 CWE-532 1 PoC

An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

CVE-2024-5057
Easy Digital Downloads Database ⚡ nuclei
9.3
CRITICAL
EPSS
64.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

CVE-2024-55978
Code Generator Pro Database
9.3
CRITICAL
EPSS
6.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation Code Generator Pro code-generator-pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through <= 1.2.

CVE-2024-57823
Raptor RDF Syntax Library General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-191 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().