6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40583
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

CVE-2024-33897
Software Genérico General
9.1
CRITICAL
EPSS
0.5%
2024 2 PoCs

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

CVE-2024-48949
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.

CVE-2024-28805
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

CVE-2024-31989
argo-cd DevOps Database
9.1
CRITICAL
EPSS
9.1%
2024 CWE-327 1 PoC

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379. Despite having installed the latest version of the VPC CNI plugin on the EKS cluster, it requires manual enablement through configuration to enforce network policies. This raises concerns that many clients might unknowingly have open access to their Redis servers. This vulnerability could lead to Privilege Escalation to the level of cluster controller, or to information leakage, aff

CVE-2024-33661
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

CVE-2024-35244
Multiple MFPs (multifunction printers) General
9.1
CRITICAL
EPSS
0.2%
2024 CWE-798 3 PoCs

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-3673
Web Directory Free Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
92.2%
2024 2 PoCs

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

CVE-2024-54879
Software Genérico Web
9.1
CRITICAL
EPSS
4.3%
2024 2 PoCs

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

CVE-2024-5806
MOVEit Transfer General
9.1
CRITICAL
EPSS
89.9%
2024 CWE-287 2 PoCs

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVE-2024-56278
WP Ultimate Exporter Web
9.1
CRITICAL
EPSS
49.1%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1.

CVE-2024-54369
Zita Site Builder General
9.1
CRITICAL
EPSS
19.3%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

CVE-2024-29643
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

CVE-2024-8673
Z-Downloads Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
5.8%
2024 1 PoC

The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

CVE-2024-32167
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVE-2024-37310
everest-core General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-122 1 PoC

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.

CVE-2024-54794
Software Genérico General
9.1
CRITICAL
EPSS
2.2%
2024 2 PoCs

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

CVE-2024-37404
Connect Secure General
9.1
CRITICAL
EPSS
86.0%
2024 1 PoC

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

CVE-2024-36394
SysAid General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-21071
Workflow Web Database
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in Oracle Workflow, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.