6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46436
Software Genérico General
8.3
HIGH
EPSS
1.0%
2024 1 PoC

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

CVE-2024-9593
Time Clock Pro Web Windows ⚡ nuclei
8.3
HIGH
EPSS
85.5%
2024 CWE-94 3 PoCs

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.

CVE-2024-41671
twisted Web
8.3
HIGH
EPSS
0.1%
2024 CWE-444 1 PoC

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

CVE-2024-35308
Pandora FMS General
8.3
HIGH
EPSS
1.0%
2024 CWE-22 1 PoC

A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.

CVE-2024-42340
CyberArk Identity Management General
8.3
HIGH
EPSS
0.1%
2024 CWE-602 1 PoC

CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

CVE-2024-41637
Software Genérico Web
8.3
HIGH
EPSS
0.3%
2024 1 PoC

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.

CVE-2024-41668
cbioportal Web
8.3
HIGH
EPSS
0.1%
2024 CWE-918 1 PoC

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, cBioPortal could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances. A fix has been released in version 6.0.12. As a workaround, one might be able to disable `/proxy` endpoint entirely via, for example, nginx.

CVE-2024-4749
wp-eMember Web Windows
8.3
HIGH
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-5410
IAP-420 Web
8.3
HIGH
EPSS
1.9%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2024-21672
Confluence Data Center General
8.3
HIGH
EPSS
7.2%
2024 3 PoCs

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version,

CVE-2024-22024
ICS General ⚡ nuclei
8.3
HIGH
EPSS
94.2%
2024 2 PoCs

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

CVE-2024-24100
Software Genérico Database
8.3
HIGH
EPSS
0.1%
2024 1 PoC

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

CVE-2024-3323
JasperReports Server General
8.3
HIGH
EPSS
0.1%
2024 1 PoC

Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.

CVE-2024-42381
Software Genérico General
8.3
HIGH
EPSS
0.4%
2024 1 PoC

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-sandboxed binary relocation phase, which occurs before a user would expect execution of downloaded package content. (237d1e783f7ee261beaba7d3f6bde22da7148b0a was the tested vulnerable version.)

CVE-2024-42995
Software Genérico General
8.3
HIGH
EPSS
0.1%
2024 1 PoC

VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

CVE-2024-11114
Chrome Windows
8.3
HIGH
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-1555
Firefox General
8.3
HIGH
EPSS
0.1%
2024 1 PoC

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

CVE-2024-27971
Premmerce Permalink Manager for WooCommerce Web
8.3
HIGH
EPSS
67.4%
2024 CWE-98 1 PoC

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.

CVE-2024-21677
Confluence Data Center General
8.3
HIGH
EPSS
2.0%
2024 2 PoCs

This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommen

CVE-2024-5420
utnserver Pro Web ⚡ nuclei
8.3
HIGH
EPSS
46.6%
2024 CWE-79 6 PoCs

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.