3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2024-33434
Software Genérico Networking
9.8
CRITICAL
EPSS
7.6%
2024 1 PoC

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.

CVE-2024-25239
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

CVE-2024-39907
1Panel Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 CWE-89 0 PoCs

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

CVE-2024-51136
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.

CVE-2024-23653
buildkit DevOps Web
9.8
CRITICAL
EPSS
10.3%
2024 CWE-863 1 PoC

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit

CVE-2024-7593
🔥 KEV vTM General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-287 6 PoCs

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

CVE-2024-33078
Software Genérico General
9.8
CRITICAL
EPSS
1.3%
2024 1 PoC

Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.

CVE-2024-38396
Software Genérico General
9.8
CRITICAL
EPSS
10.3%
2024 3 PoCs

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

CVE-2024-54804
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.

CVE-2024-52335
syngo.plaza VB30E Database
9.8
CRITICAL
EPSS
1.2%
2024 CWE-89 1 PoC

A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.

CVE-2024-22633
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.

CVE-2024-37782
Software Genérico Windows
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.

CVE-2024-13375
Adifier System Web Windows
9.8
CRITICAL
EPSS
10.6%
2024 CWE-620 1 PoC

The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the adifier_recover() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVE-2024-8517
SPIP Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 CWE-73 2 PoCs

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

CVE-2024-23708
Android General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-8381
Firefox General
9.8
CRITICAL
EPSS
11.6%
2024 1 PoC

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVE-2024-57045
Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
66.8%
2024 0 PoCs

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

CVE-2024-33375
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.