6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-55981
Nabz Image Gallery Database
9.3
CRITICAL
EPSS
25.2%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery nabz-image-gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through <= v1.00.

CVE-2024-2796
Akana API Platform Web
9.3
CRITICAL
EPSS
0.4%
2024 CWE-918 1 PoC

A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

CVE-2024-27954
Automatic General ⚡ nuclei
9.3
CRITICAL
EPSS
93.4%
2024 CWE-22 4 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

CVE-2024-32128
Realtyna Organic IDX plugin Database ⚡ nuclei
9.3
CRITICAL
EPSS
11.0%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.

CVE-2024-9166
Atemio AM 520 HD Full HD Satellite Receiver General ⚡ nuclei
9.3
CRITICAL
EPSS
3.7%
2024 CWE-78 2 PoCs

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVE-2024-6913
ProcessPlus Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-250 2 PoCs

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-9464
Expedition Web Networking
9.3
CRITICAL
EPSS
85.3%
2024 CWE-78 3 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-55988
Navayan CSV Export Database
9.3
CRITICAL
EPSS
32.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.

CVE-2024-24759
mindsdb General ⚡ nuclei
9.3
CRITICAL
EPSS
82.8%
2024 CWE-918 0 PoCs

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

CVE-2024-55980
Wr Age Verification Database
9.3
CRITICAL
EPSS
6.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0.

CVE-2024-7332
CP450 General ⚡ nuclei
9.3
CRITICAL
EPSS
92.1%
2024 CWE-259 0 PoCs

A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-30498
CRM Perks Forms Database ⚡ nuclei
9.3
CRITICAL
EPSS
15.0%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

CVE-2024-6915
Artifactory General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-20 1 PoC

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

CVE-2024-9465
🔥 KEV Expedition Web Networking Database ⚡ nuclei
9.2
CRITICAL
EPSS
94.3%
2024 CWE-89 5 PoCs

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVE-2024-10218
TIBCO Hawk Web
9.2
CRITICAL
EPSS
0.1%
2024 1 PoC

XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence

CVE-2024-58298
Compuware iStrobe Web General
9.2
CRITICAL
EPSS
2.0%
2024 CWE-434 1 PoC

Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicious JSP files through a path traversal in the file upload form. Attackers can exploit the 'fileName' parameter to upload a web shell and execute arbitrary commands by sending POST requests to the uploaded JSP endpoint.

CVE-2024-10914
DNS-320 General ⚡ nuclei
9.2
CRITICAL
EPSS
94.0%
2024 CWE-78 14 PoCs

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2024-10217
TIBCO Hawk Web
9.2
CRITICAL
EPSS
0.1%
2024 1 PoC

XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence

CVE-2024-5217
🔥 KEV Now Platform General ⚡ nuclei
9.2
CRITICAL
EPSS
94.1%
2024 CWE-184 2 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-10915
DNS-320 General ⚡ nuclei
9.2
CRITICAL
EPSS
94.1%
2024 CWE-78 1 PoC

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.