6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0324
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Web Windows
8.2
HIGH
EPSS
37.3%
2024 CWE-284 1 PoC

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.

CVE-2024-24570
cms Web
8.2
HIGH
EPSS
1.4%
2024 CWE-79 2 PoCs

Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the control panel. Additionally, if the XSS is crafted in a specific way, the "copy password reset link" feature may be exploited to gain access to a user's password reset token and gain access to their account. The authorized user is required to execute the XSS in order for the vulnerability to occur. In versions 4.46.0 and 3.4.

CVE-2024-21527
github.com/gotenberg/gotenberg/v8/pkg/gotenberg General
8.2
HIGH
EPSS
0.2%
2024 CWE-918 3 PoCs

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when a request is made to a file via localhost, such as <iframe src="\\localhost/etc/passwd">. By exploiting this vulnerability, an attacker can achieve local file inclusion, allowing of sensitive files read on the host system. Workaround An al

CVE-2024-47773
discourse General
8.2
HIGH
EPSS
7.9%
2024 CWE-610 1 PoC

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.

CVE-2024-6507
Software Genérico Web
8.1
HIGH
EPSS
0.3%
2024 CWE-78 1 PoC

Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

CVE-2024-56883
Software Genérico General
8.1
HIGH
EPSS
3.1%
2024 2 PoCs

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the option to do so in the user interface. To do this, a valid request to create a course simply needs to be modified, so that the current user ID in the "id" parameter is replaced with the ID of another user.

CVE-2024-22259
Spring Framework Web
8.1
HIGH
EPSS
56.4%
2024 2 PoCs

Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.

CVE-2024-22773
Software Genérico Networking
8.1
HIGH
EPSS
0.1%
2024 3 PoCs

Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

CVE-2024-56903
Software Genérico Web
8.1
HIGH
EPSS
0.3%
2024 1 PoC

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

CVE-2024-29153
Software Genérico General
8.1
HIGH
EPSS
0.7%
2024 2 PoCs

A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, and Exynos Modem 5300 that involves incorrect authorization of LTE NAS messages and leads to downgrading to lower network generations and repeated DDOS.

CVE-2024-34391
Software Genérico General
8.1
HIGH
EPSS
3.2%
2024 CWE-843 1 PoC

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).

CVE-2024-56174
Software Genérico Web
8.1
HIGH
EPSS
0.8%
2024 1 PoC

In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.

CVE-2024-38473
Apache HTTP Server Web ⚡ nuclei
8.1
HIGH
EPSS
88.4%
2024 CWE-116 2 PoCs

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVE-2024-6387
Software Genérico Networking
8.1
HIGH
EPSS
48.4%
2024 CWE-364 105 PoCs

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVE-2024-0763
mintplex-labs/anything-llm General
8.1
HIGH
EPSS
0.7%
2024 CWE-22 1 PoC

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.

CVE-2024-10220
kubelet DevOps
8.1
HIGH
EPSS
39.6%
2024 CWE-22 7 PoCs

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

CVE-2024-5721
Unified SecOps Platform Web
8.1
HIGH
EPSS
63.2%
2024 CWE-306 1 PoC

Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the cluster HTTP API, which listens on TCP port 1924 when enabled. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-2416

CVE-2024-43582
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
26.0%
2024 CWE-416 1 PoC

Remote Desktop Protocol Server Remote Code Execution Vulnerability

CVE-2024-48325
Software Genérico Web Database
8.1
HIGH
EPSS
12.6%
2024 1 PoC

Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, allowing an unauthenticated remote attacker to inject malicious SQL commands.

CVE-2024-43425
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
89.3%
2024 3 PoCs

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.