3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-56897
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

CVE-2024-9537
🔥 KEV SL1 General
9.8
CRITICAL
EPSS
63.9%
2024 4 PoCs

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

CVE-2024-34313
Software Genérico General
9.8
CRITICAL
EPSS
24.7%
2024 1 PoC

An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.

CVE-2024-21511
mysql2 Database
9.8
CRITICAL
EPSS
0.1%
2024 CWE-94 1 PoC

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

CVE-2024-57604
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

CVE-2024-3136
MasterStudy LMS WordPress Plugin – for Online Courses and Education Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
54.2%
2024 CWE-98 1 PoC

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-5084
Hash Form – Drag & Drop Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2024 CWE-434 7 PoCs

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-27145
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
0.3%
2024 CWE-22 2 PoCs

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions

CVE-2024-2667
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.7%
2024 CWE-434 2 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.

CVE-2024-55099
Software Genérico Web Database
9.8
CRITICAL
EPSS
21.0%
2024 2 PoCs

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVE-2024-2921
Server General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.

CVE-2024-24398
Software Genérico General
9.8
CRITICAL
EPSS
30.5%
2024 2 PoCs

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

CVE-2024-55875
http4k Web
9.8
CRITICAL
EPSS
7.2%
2024 CWE-200 1 PoC

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side Request Forgery and even execute code under some circumstances. Version 5.41.0.0 contains a patch for the issue.

CVE-2024-27776
DeviceHub General
9.8
CRITICAL
EPSS
0.6%
2024 CWE-22 1 PoC

MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE

CVE-2024-29650
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 2 PoCs

An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.

CVE-2024-45274
mbNET.mini General
9.8
CRITICAL
EPSS
3.6%
2024 CWE-306 2 PoCs

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

CVE-2024-32444
RealHomes General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.

CVE-2024-13159
🔥 KEV Endpoint Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-55556
Software Genérico Web
9.8
CRITICAL
EPSS
84.7%
2024 1 PoC

A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies on an attacker obtaining Laravel's secret APP_KEY, which would allow them to decrypt and manipulate session cookies (laravel_session) containing serialized data. By altering this data and re-encrypting it with the APP_KEY, the attacker could trigger arbitrary deserialization on th

CVE-2024-3495
Country State City Dropdown CF7 Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2024 CWE-89 2 PoCs

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.