3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22638
Software Genérico Web
9.8
CRITICAL
EPSS
6.4%
2024 2 PoCs

liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.

CVE-2024-45169
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 2 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution via the \xB0\x00\x3c byte sequence.

CVE-2024-9989
Crypto Tool Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.6%
2024 CWE-288 0 PoCs

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

CVE-2024-38887
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.

CVE-2024-40446
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script

CVE-2024-44921
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

CVE-2024-2771
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
27.1%
2024 CWE-862 1 PoC

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.

CVE-2024-50483
Meetup General
9.8
CRITICAL
EPSS
54.0%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

CVE-2024-52382
Matix Popup Builder General
9.8
CRITICAL
EPSS
17.4%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0.

CVE-2024-33374
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

CVE-2024-25843
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

CVE-2024-48307
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 1 PoC

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

CVE-2024-21508
mysql2 Database
9.8
CRITICAL
EPSS
46.2%
2024 CWE-94 2 PoCs

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVE-2024-23746
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).

CVE-2024-50588
Elefant General
9.8
CRITICAL
EPSS
0.4%
2024 CWE-1393 2 PoCs

An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM").

CVE-2024-29849
Backup & Replication General
9.8
CRITICAL
EPSS
53.6%
2024 1 PoC

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

CVE-2024-23739
Software Genérico General
9.8
CRITICAL
EPSS
35.8%
2024 2 PoCs

An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-40711
🔥 KEV Backup and Recovery General ⚡ nuclei
9.8
CRITICAL
EPSS
68.2%
2024 4 PoCs

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

CVE-2024-57035
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.