3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1207
Booking Calendar Web Database Windows
9.8
CRITICAL
EPSS
78.7%
2024 CWE-89 1 PoC

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-31819
Software Genérico Web
9.8
CRITICAL
EPSS
83.1%
2024 4 PoCs

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

CVE-2024-10586
Debug Tool Web Windows
9.8
CRITICAL
EPSS
58.9%
2024 CWE-862 2 PoCs

The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution. CVE-2024-52416 may be a duplicate of this issue.

CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-89 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-25897
Software Genérico Web Database
9.8
CRITICAL
EPSS
12.3%
2024 1 PoC

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

CVE-2024-25254
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

CVE-2024-6127
Empire Web
9.8
CRITICAL
EPSS
66.1%
2024 CWE-22 2 PoCs

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVE-2024-28213
nGrinder General
9.8
CRITICAL
EPSS
8.1%
2024 CWE-502 1 PoC

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.

CVE-2024-33775
Software Genérico General
9.8
CRITICAL
EPSS
3.4%
2024 1 PoC

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

CVE-2024-37393
Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 3 PoCs

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

CVE-2024-54676
Apache OpenMeetings Web
9.8
CRITICAL
EPSS
6.1%
2024 CWE-502 1 PoC

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.

CVE-2024-4883
WhatsUp Gold Web
9.8
CRITICAL
EPSS
92.2%
2024 CWE-77 1 PoC

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

CVE-2024-25180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 4 PoCs

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.

CVE-2024-30982
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

CVE-2024-10508
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Web Windows
9.8
CRITICAL
EPSS
15.3%
2024 CWE-230 3 PoCs

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.

CVE-2024-32640
MasaCMS Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 6 PoCs

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

CVE-2024-6396
aimhubio/aim General ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2024 CWE-29 0 PoCs

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.

CVE-2024-25249
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2024 1 PoC

An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-40117
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.

CVE-2024-28713
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.