3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-30502
WP Travel Engine Database ⚡ nuclei
9.3
CRITICAL
EPSS
18.4%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.

CVE-2024-55547
IAP-420 General
9.3
CRITICAL
EPSS
37.2%
2024 CWE-77 2 PoCs

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

CVE-2024-55976
Critical Site Intel Database
9.3
CRITICAL
EPSS
35.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mikeleembruggen Critical Site Intel critical-site-intel-stats allows SQL Injection.This issue affects Critical Site Intel: from n/a through <= 1.0.

CVE-2024-58286
dizqueTV General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-78 1 PoC

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

CVE-2024-0521
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-94 1 PoC

Code Injection in paddlepaddle/paddle

CVE-2024-35304
Pandora FMS General
9.3
CRITICAL
EPSS
1.8%
2024 CWE-78 1 PoC

System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.

CVE-2024-42009
🔥 KEV Software Genérico Web ⚡ nuclei
9.3
CRITICAL
EPSS
91.4%
2024 5 PoCs

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

CVE-2024-13502
NTC2218, NTC2250, NTC2299 General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion.This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The `commit_multicast` page used to configure multicasts in the modem's web administration interface uses improperly parses incoming data from the request before passing it to an `eval` statement in a bash script. This allows attackers to inject arbitrary shell commands.

CVE-2024-0817
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-77 1 PoC

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

CVE-2024-6912
ProcessPlus Database Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-798 2 PoCs

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-13990
eScan AV General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-295 3 PoCs

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-the-middle (MitM) attack and substitute malicious update payloads for legitimate ones. The eScan AV client accepted these substituted packages and executed or loaded their components (including sideloaded DLLs and Java/installer payloads), enabling remote code execution on affected systems. MicroWorld eScan confirmed remediation of the update mechanism on 2023

CVE-2024-54152
angular-expressions General
9.3
CRITICAL
EPSS
25.1%
2024 CWE-94 1 PoC

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system. With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system. The problem has been patched in version 1.4.3 of Angular Expressions. Two possible workarounds are available. One may either disable access to `__proto__` globally or make sure that one uses the function with just one argument.

CVE-2024-0815
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

CVE-2024-9129
Zend Server General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-134 1 PoC

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

CVE-2024-22252
VMware ESXi General
9.3
CRITICAL
EPSS
0.2%
2024 1 PoC

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

CVE-2024-51818
Fancy Product Designer Database
9.3
CRITICAL
EPSS
19.3%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.

CVE-2024-30490
ProfileGrid Database ⚡ nuclei
9.3
CRITICAL
EPSS
14.4%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

CVE-2024-39373
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-77 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.

CVE-2024-0012
🔥 KEV Cloud NGFW Web Networking Cloud ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-306 13 PoCs

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice d

CVE-2024-39375
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-603 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.