6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5315
ERP CMS Web Database ⚡ nuclei
9.1
CRITICAL
EPSS
63.0%
2024 CWE-89 0 PoCs

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

CVE-2024-21887
🔥 KEV ICS General ⚡ nuclei
9.1
CRITICAL
EPSS
94.4%
2024 9 PoCs

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CVE-2024-5450
Bug Library Web Windows
9.1
CRITICAL
EPSS
2.1%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

CVE-2024-34451
Software Genérico General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

CVE-2024-40422
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.6%
2024 4 PoCs

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

CVE-2024-10474
Focus for iOS General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.

CVE-2024-32113
🔥 KEV Apache OFBiz Web ⚡ nuclei
9.1
CRITICAL
EPSS
94.0%
2024 CWE-22 5 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

CVE-2024-42049
Software Genérico Windows
9.1
CRITICAL
EPSS
5.8%
2024 1 PoC

TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

CVE-2024-42885
Software Genérico Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.

CVE-2024-20720
Adobe Commerce General
9.1
CRITICAL
EPSS
7.2%
2024 CWE-78 1 PoC

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

CVE-2024-34987
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.0%
2024 2 PoCs

A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.

CVE-2024-34783
EPM Database
9.1
CRITICAL
EPSS
50.8%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-31989
argo-cd DevOps Database
9.1
CRITICAL
EPSS
9.1%
2024 CWE-327 1 PoC

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379. Despite having installed the latest version of the VPC CNI plugin on the EKS cluster, it requires manual enablement through configuration to enforce network policies. This raises concerns that many clients might unknowingly have open access to their Redis servers. This vulnerability could lead to Privilege Escalation to the level of cluster controller, or to information leakage, aff

CVE-2024-23717
Android General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-6366
User Profile Builder Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
91.5%
2024 3 PoCs

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

CVE-2024-48942
Software Genérico General
9.1
CRITICAL
EPSS
0.5%
2024 1 PoC

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.

CVE-2024-8673
Z-Downloads Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
5.8%
2024 1 PoC

The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

CVE-2024-2862
LG LED Assistant General ⚡ nuclei
9.1
CRITICAL
EPSS
74.5%
2024 CWE-287 0 PoCs

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

CVE-2024-38821
Spring Web
9.1
CRITICAL
EPSS
13.1%
2024 3 PoCs

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's static resources support * It must have a non-permitAll authorization rule applied to the static resources support

CVE-2024-56249
WPMasterToolKit General
9.1
CRITICAL
EPSS
41.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.