3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-56059
Partners General
9.8
CRITICAL
EPSS
32.3%
2024 CWE-1321 1 PoC

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.

CVE-2024-45265
Software Genérico Web Database
9.8
CRITICAL
EPSS
17.6%
2024 1 PoC

A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

CVE-2024-3552
Web Directory Free Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 4 PoCs

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 10 PoCs

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-9234
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2024 CWE-862 3 PoCs

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.

CVE-2024-31777
Software Genérico Web
9.8
CRITICAL
EPSS
30.4%
2024 1 PoC

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

CVE-2024-36681
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.

CVE-2024-44410
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

CVE-2024-22922
Software Genérico Web
9.8
CRITICAL
EPSS
0.9%
2024 2 PoCs

An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php

CVE-2024-25169
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

CVE-2024-9942
WPGYM - Wordpress Gym Management System Web Windows
9.8
CRITICAL
EPSS
5.0%
2024 CWE-434 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-57450
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

CVE-2024-36057
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data can be controlled by an attacker and is directly included in a system command, i.e., an attack can occur via malicious filenames after uploading a .zip file and clicking Process Images.

CVE-2024-38612
Linux General
9.8
CRITICAL
EPSS
0.2%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregister_family() isn't called. This issue exist since commit 46738b1317e1 ("ipv6: sr: add option to control lwtunnel support"), and commit 5559cea2d5aa ("ipv6: sr: fix possible use-after-free and null-ptr-deref") replaced unregister_pernet_subsys() with genl_unregister_family() in this error path.

CVE-2024-11350
AdForest Web Windows
9.8
CRITICAL
EPSS
0.3%
2024 CWE-640 1 PoC

The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVE-2024-12857
AdForest Web Windows
9.8
CRITICAL
EPSS
0.6%
2024 CWE-288 1 PoC

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.

CVE-2024-45490
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

CVE-2024-36058
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.

CVE-2024-23108
FortiSIEM Web Networking
9.7
CRITICAL
EPSS
90.4%
2024 CWE-78 2 PoCs

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

CVE-2024-34716
PrestaShop Web
9.7
CRITICAL
EPSS
36.7%
2024 CWE-79 4 PoCs

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of t