6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-35241
composer Web
8.8
HIGH
EPSS
0.4%
2024 CWE-77 2 PoCs

Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.

CVE-2024-28741
Software Genérico Web
8.8
HIGH
EPSS
88.0%
2024 3 PoCs

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

CVE-2024-22263
Spring Cloud Skipper DevOps Web Cloud
8.8
HIGH
EPSS
77.7%
2024 1 PoC

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

CVE-2024-23767
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.

CVE-2024-8904
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-21254
Oracle BI Publisher Web Database
8.8
HIGH
EPSS
1.0%
2024 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-41334
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution.

CVE-2024-3476
Side Menu Lite Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2024-38457
Software Genérico Web
8.8
HIGH
EPSS
6.6%
2024 1 PoC

Xenforo before 2.2.16 allows CSRF.

CVE-2024-57376
Software Genérico General
8.8
HIGH
EPSS
51.9%
2024 2 PoCs

Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.

CVE-2024-34448
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

CVE-2024-41589
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

CVE-2024-4352
Tutor LMS Pro Web Database Windows
8.8
HIGH
EPSS
23.3%
2024 CWE-862 1 PoC

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the ‘year’ parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sens

CVE-2024-53345
Software Genérico General
8.8
HIGH
EPSS
6.8%
2024 1 PoC

An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-0858
Innovs HR Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.

CVE-2024-7256
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2024-26362
Software Genérico Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

CVE-2024-22899
Software Genérico General
8.8
HIGH
EPSS
21.2%
2024 2 PoCs

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

CVE-2024-5793
Houzez Theme - Functionality Web Database Windows
8.8
HIGH
EPSS
0.7%
2024 CWE-89 1 PoC

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-50858
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.