6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22983
Software Genérico Web Database
8.1
HIGH
EPSS
0.9%
2024 3 PoCs

SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.

CVE-2024-10327
Okta Verify for iOS General
8.1
HIGH
EPSS
0.1%
2024 CWE-287 1 PoC

A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the notification banner and selects an option, both options allow the authentication to succeed. The ContextExtension feature is one of several push mechanisms available when using Okta Verify Push on iOS devices. The vulnerable flows include: * When a user is presented with a notification on a locked screen, the user presses on t

CVE-2024-41973
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.8%
2024 CWE-35 1 PoC

A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.

CVE-2024-24892
migration-tools Web
8.1
HIGH
EPSS
0.2%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulnerability is associated with program files https://gitee.Com/openeuler/migration-tools/blob/master/index.Py. This issue affects migration-tools: from 1.0.0 through 1.0.1.

CVE-2024-41971
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.8%
2024 CWE-22 1 PoC

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

CVE-2024-3183
Software Genérico Windows
8.1
HIGH
EPSS
21.2%
2024 CWE-916 1 PoC

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key is a hash of a public per-principal randomly-generated salt and the user’s password. If a principal is compromised it means the attacker would be able to retrieve tickets encrypted to any principal, all of them being encrypted by their own key directly. By taking these tickets

CVE-2024-24336
Software Genérico Web
8.1
HIGH
EPSS
0.2%
2024 2 PoCs

A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users visiting the affected page, via the 'Circulation note' and ‘Patrons Restriction’ components.

CVE-2024-21282
Oracle Financials Web Database
8.1
HIGH
EPSS
0.8%
2024 1 PoC

Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials accessible data. CVSS 3.1 Base Score 8.1 (Confi

CVE-2024-21271
Oracle Field Service Web Database
8.1
HIGH
EPSS
1.2%
2024 1 PoC

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Field Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3

CVE-2024-21267
Oracle Cost Management Web Database
8.1
HIGH
EPSS
1.2%
2024 1 PoC

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base

CVE-2024-5167
CM Email Registration Blacklist and Whitelist Web Windows
8.1
HIGH
EPSS
0.2%
2024 1 PoC

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack

CVE-2024-56903
Software Genérico Web
8.1
HIGH
EPSS
0.3%
2024 1 PoC

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

CVE-2024-57783
Dot Web
8.1
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVE-2024-56174
Software Genérico Web
8.1
HIGH
EPSS
0.8%
2024 1 PoC

In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.

CVE-2024-57030
Software Genérico Web
8.1
HIGH
EPSS
0.7%
2024 1 PoC

Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.

CVE-2024-21277
Oracle MES for Process Manufacturing Web Database
8.1
HIGH
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle MES for Process Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle

CVE-2024-27876
iOS and iPadOS General
8.1
HIGH
EPSS
0.0%
2024 1 PoC

A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

CVE-2024-36598
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 2 PoCs

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

CVE-2024-11700
Firefox General
8.1
HIGH
EPSS
0.3%
2024 1 PoC

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVE-2024-21266
Oracle Advanced Pricing Web Database
8.1
HIGH
EPSS
1.2%
2024 1 PoC

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data. CVSS 3.1 Base