6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28805
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

CVE-2024-48949
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.

CVE-2024-33897
Software Genérico General
9.1
CRITICAL
EPSS
0.5%
2024 2 PoCs

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

CVE-2024-57727
🔥 KEV Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
94.0%
2024 1 PoC

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

CVE-2024-47945
IoT Interface & CMC III Processing Unit General
9.1
CRITICAL
EPSS
0.4%
2024 CWE-340 1 PoC

The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid session IDs, leading to unauthorized access to user sessions. This is not only due to the use of an (insecure) rand() function call but also because of missing initialization via srand(). As a result only the PIDs are effectively used as seed.

CVE-2024-7387
Software Genérico DevOps
9.1
CRITICAL
EPSS
0.8%
2024 CWE-250 1 PoC

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

CVE-2024-54880
Software Genérico Web
9.1
CRITICAL
EPSS
5.5%
2024 2 PoCs

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

CVE-2024-29868
Apache StreamPipes Web ⚡ nuclei
9.1
CRITICAL
EPSS
78.4%
2024 CWE-338 1 PoC

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

CVE-2024-46627
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
91.7%
2024 1 PoC

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

CVE-2024-37899
xwiki-platform General
9.1
CRITICAL
EPSS
14.1%
2024 CWE-94 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the user profile before getting an admin to disable the user account. To reproduce, as a user without script nor programming rights, edit the about section of your user profile and add `{{groovy}}services.logging.getLogger("attacker").error("Hello from Groovy!"){{/groovy}}`. As an admin, go to the user profile and click the "Disable this account" butto

CVE-2024-45163
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 4 PoCs

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.

CVE-2024-25413
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVE-2024-34779
EPM Database
9.1
CRITICAL
EPSS
32.9%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-27448
Software Genérico General
9.1
CRITICAL
EPSS
13.0%
2024 1 PoC

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

CVE-2024-40898
Apache HTTP Server Web Windows
9.1
CRITICAL
EPSS
0.7%
2024 CWE-918 4 PoCs

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

CVE-2024-7385
WP Simple HTML Sitemap Web Database Windows
9.1
CRITICAL
EPSS
13.1%
2024 CWE-89 1 PoC

The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-5973
MasterStudy LMS WordPress Plugin Web Windows
9.1
CRITICAL
EPSS
0.9%
2024 1 PoC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVE-2024-36497
WINSelect (Standard + Enterprise) General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-312 2 PoCs

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

CVE-2024-37770
Software Genérico General
9.1
CRITICAL
EPSS
11.0%
2024 1 PoC

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CVE-2024-37388
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.