3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21071
Workflow Web Database
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in Oracle Workflow, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.

CVE-2024-31345
Auto Poster General
9.1
CRITICAL
EPSS
1.3%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

CVE-2024-7525
Firefox General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

CVE-2024-26503
Software Genérico Web
9.1
CRITICAL
EPSS
2.2%
2024 1 PoC

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to certbadge.php endpoint.

CVE-2024-6584
Jetpack Boost General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

CVE-2024-57766
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

CVE-2024-30896
Software Genérico Database Cloud
9.1
CRITICAL
EPSS
31.5%
2024 1 PoC

InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organiz

CVE-2024-48144
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-28987
🔥 KEV Web Help Desk General ⚡ nuclei
9.1
CRITICAL
EPSS
94.3%
2024 CWE-798 7 PoCs

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

CVE-2024-48145
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-25735
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2024 2 PoCs

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

CVE-2024-3050
Site Reviews Web Windows
9.1
CRITICAL
EPSS
0.8%
2024 1 PoC

The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking

CVE-2024-43401
xwiki-platform General
9.1
CRITICAL
EPSS
1.5%
2024 CWE-269 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.

CVE-2024-37285
Kibana Web Database
9.1
CRITICAL
EPSS
1.1%
2024 CWE-502 2 PoCs

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv  and Kibana privileges https://www.elastic.co/guide/en/fleet/current/fleet-roles-and-privileges.html  assigned to them. The following Elasticsearch indices permissions are required * write privilege on the system indices .k

CVE-2024-36394
SysAid General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-37310
everest-core General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-122 1 PoC

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.

CVE-2024-32167
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVE-2024-54369
Zita Site Builder General
9.1
CRITICAL
EPSS
19.3%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

CVE-2024-35293
Series 700 General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-306 2 PoCs

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.

CVE-2024-32843
EPM Database
9.1
CRITICAL
EPSS
9.1%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.