3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28752
Apache CXF Web ⚡ nuclei
9.3
CRITICAL
EPSS
50.8%
2024 CWE-918 1 PoC

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

CVE-2024-8752
WebIQ Windows ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-22 1 PoC

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

CVE-2024-6060
Webscopes Web
9.3
CRITICAL
EPSS
0.1%
2024 CWE-532 1 PoC

An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

CVE-2024-55982
Share Buttons – Social Media Database
9.3
CRITICAL
EPSS
31.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.

CVE-2024-50491
RSVP ME Database
9.3
CRITICAL
EPSS
37.7%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

CVE-2024-49681
WP Sessions Time Monitoring Full Automatic Database
9.3
CRITICAL
EPSS
51.3%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.

CVE-2024-6912
ProcessPlus Database Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-798 2 PoCs

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-9464
Expedition Web Networking
9.3
CRITICAL
EPSS
85.3%
2024 CWE-78 3 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-6913
ProcessPlus Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-250 2 PoCs

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-33544
WZone Database
9.3
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

CVE-2024-7988
ThinManager® ThinServer™ General
9.3
CRITICAL
EPSS
12.6%
2024 CWE-20 1 PoC

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

CVE-2024-58286
dizqueTV General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-78 1 PoC

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

CVE-2024-9166
Atemio AM 520 HD Full HD Satellite Receiver General ⚡ nuclei
9.3
CRITICAL
EPSS
3.7%
2024 CWE-78 2 PoCs

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVE-2024-0012
🔥 KEV Cloud NGFW Web Networking Cloud ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-306 13 PoCs

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice d

CVE-2024-7024
Chrome General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-39375
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-603 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.

CVE-2024-0521
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-94 1 PoC

Code Injection in paddlepaddle/paddle

CVE-2024-5910
🔥 KEV Expedition Networking ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-306 1 PoC

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

CVE-2024-0817
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-77 1 PoC

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

CVE-2024-5057
Easy Digital Downloads Database ⚡ nuclei
9.3
CRITICAL
EPSS
64.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.