17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-36393
SysAid Database
9.9
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-31390
Breakdance General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 3 PoCs

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

CVE-2024-9014
pgAdmin 4 General ⚡ nuclei
9.9
CRITICAL
EPSS
92.9%
2024 2 PoCs

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

CVE-2024-42327
Zabbix Web Database
9.9
CRITICAL
EPSS
91.4%
2024 CWE-89 9 PoCs

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVE-2024-31380
Oxygen Builder General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

CVE-2024-31286
WP Photo Album Plus General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

CVE-2024-2044
pgAdmin 4 Windows
9.9
CRITICAL
EPSS
83.5%
2024 1 PoC

pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.

CVE-2024-39930
Software Genérico Networking Windows
9.9
CRITICAL
EPSS
11.9%
2024 4 PoCs

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.

CVE-2024-37288
Kibana Web
9.9
CRITICAL
EPSS
1.9%
2024 CWE-502 2 PoCs

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-security.html  and have configured an Amazon Bedrock connector https://www.elastic.co/guide/en/security/current/assistant-connect-to-bedrock.html .

CVE-2024-3105
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts Web Windows
9.9
CRITICAL
EPSS
57.9%
2024 CWE-94 1 PoC

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.

CVE-2024-33699
WBR-6012 Networking
9.9
CRITICAL
EPSS
7.2%
2024 CWE-620 2 PoCs

The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.

CVE-2024-49653
Portfolleo General
9.9
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.

CVE-2024-42515
Software Genérico Web
9.9
CRITICAL
EPSS
0.2%
2024 1 PoC

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry.

CVE-2024-37762
Software Genérico General
9.9
CRITICAL
EPSS
28.0%
2024 1 PoC

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2024-21010
Hospitality Simphony Web Database
9.9
CRITICAL
EPSS
1.0%
2024 1 PoC

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality,

CVE-2024-27956
Automatic Database ⚡ nuclei
9.9
CRITICAL
EPSS
93.8%
2024 CWE-89 17 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

CVE-2024-9463
🔥 KEV Expedition Web Networking ⚡ nuclei
9.9
CRITICAL
EPSS
94.2%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-0455
mintplex-labs/anything-llm Web
9.9
CRITICAL
EPSS
0.2%
2024 CWE-918 2 PoCs

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could put in the URL ``` http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance ``` which is a special IP and URL that resolves only when the request comes from within an EC2 instance. This would allow the user to see the connection/secret credentials for their specific instance and be able to manage it regardless of who deployed it. The user would have to have pre-existing knowledge of the hosting infra

CVE-2024-12583
Dynamics 365 Integration Web Windows
9.9
CRITICAL
EPSS
9.1%
2024 CWE-1336 1 PoC

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVE-2024-54262
Import Export For WooCommerce General
9.9
CRITICAL
EPSS
54.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.