33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1676
Chrome General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-11635
Iptanus File Upload Web Windows
9.8
CRITICAL
EPSS
23.7%
2024 CWE-94 1 PoC

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

CVE-2024-56071
Simple Dashboard General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.

CVE-2024-48359
Software Genérico General
9.8
CRITICAL
EPSS
38.2%
2024 1 PoC

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

CVE-2024-13513
Oliver POS – A WooCommerce Point of Sale (POS) Web Windows
9.8
CRITICAL
EPSS
0.1%
2024 CWE-862 1 PoC

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.

CVE-2024-1015
E-DDC3.3 General
9.8
CRITICAL
EPSS
3.7%
2024 CWE-94 1 PoC

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.

CVE-2024-55956
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 3 PoCs

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

CVE-2024-34945
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.

CVE-2024-0244
Satera MF750C Series General
9.8
CRITICAL
EPSS
0.5%
2024 CWE-787 2 PoCs

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SENSYS MF754Cdw/C1333iF firmware v03.07 and earlier sold in Europe.

CVE-2024-7954
SPIP Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2024 CWE-95 13 PoCs

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

CVE-2024-44541
Software Genérico Database
9.8
CRITICAL
EPSS
2.9%
2024 1 PoC

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

CVE-2024-22320
Operational Decision Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
90.8%
2024 CWE-502 1 PoC

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

CVE-2024-35373
Software Genérico Web
9.8
CRITICAL
EPSS
2.2%
2024 1 PoC

Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

CVE-2024-6459
News Element Elementor Blog Magazine Web Windows
9.8
CRITICAL
EPSS
5.8%
2024 1 PoC

The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-21546
unisharp/laravel-filemanager Web
9.8
CRITICAL
EPSS
4.4%
2024 CWE-94 2 PoCs

Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.

CVE-2024-54820
Software Genérico Database
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

CVE-2024-29973
NAS326 firmware Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-78 11 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVE-2024-39705
Software Genérico General
9.8
CRITICAL
EPSS
10.8%
2024 1 PoC

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

CVE-2024-4320
parisneo/lollms-webui Networking
9.8
CRITICAL
EPSS
66.2%
2024 CWE-29 1 PoC

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to improper handling of the `name` parameter in the `ExtensionBuilder().build_extension()` method, which allows for local file inclusion (LFI) leading to arbitrary code execution. An attacker can exploit this vulnerability by crafting a malicious `name` parameter that causes the server to load and execute a `__init__.py` file from an arbitrary location, such as t

CVE-2024-43441
Apache HugeGraph-Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
90.4%
2024 CWE-302 0 PoCs

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.