6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-49653
Portfolleo General
9.9
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.

CVE-2024-42515
Software Genérico Web
9.9
CRITICAL
EPSS
0.2%
2024 1 PoC

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry.

CVE-2024-37762
Software Genérico General
9.9
CRITICAL
EPSS
28.0%
2024 1 PoC

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2024-21010
Hospitality Simphony Web Database
9.9
CRITICAL
EPSS
1.0%
2024 1 PoC

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality,

CVE-2024-27956
Automatic Database ⚡ nuclei
9.9
CRITICAL
EPSS
93.8%
2024 CWE-89 17 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

CVE-2024-9463
🔥 KEV Expedition Web Networking ⚡ nuclei
9.9
CRITICAL
EPSS
94.2%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-0455
mintplex-labs/anything-llm Web
9.9
CRITICAL
EPSS
0.2%
2024 CWE-918 2 PoCs

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could put in the URL ``` http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance ``` which is a special IP and URL that resolves only when the request comes from within an EC2 instance. This would allow the user to see the connection/secret credentials for their specific instance and be able to manage it regardless of who deployed it. The user would have to have pre-existing knowledge of the hosting infra

CVE-2024-12583
Dynamics 365 Integration Web Windows
9.9
CRITICAL
EPSS
9.1%
2024 CWE-1336 1 PoC

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVE-2024-54262
Import Export For WooCommerce General
9.9
CRITICAL
EPSS
54.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.

CVE-2024-42448
Service Provider Console General
9.9
CRITICAL
EPSS
64.4%
2024 2 PoCs

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

CVE-2024-6386
WPML Web Windows
9.9
CRITICAL
EPSS
73.9%
2024 CWE-1336 2 PoCs

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVE-2024-0402
GitLab DevOps
9.9
CRITICAL
EPSS
40.8%
2024 CWE-22 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVE-2024-24142
Software Genérico Database
9.8
CRITICAL
EPSS
10.3%
2024 1 PoC

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

CVE-2024-35339
Software Genérico General
9.8
CRITICAL
EPSS
3.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.

CVE-2024-57602
Software Genérico Web
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

CVE-2024-41702
SiberianCMS v5.0.8 Web Database
9.8
CRITICAL
EPSS
0.2%
2024 CWE-89 1 PoC

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-36526
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

CVE-2024-6611
Firefox Web
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVE-2024-30163
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
46.4%
2024 1 PoC

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.

CVE-2024-23759
Software Genérico General
9.8
CRITICAL
EPSS
67.1%
2024 1 PoC

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.