3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-24707
Cwicly General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.

CVE-2024-39943
Software Genérico Web
9.9
CRITICAL
EPSS
78.3%
2024 4 PoCs

rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).

CVE-2024-37361
Pentaho Data Integration & Analytics General
9.9
CRITICAL
EPSS
0.4%
2024 CWE-502 1 PoC

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to le

CVE-2024-52429
WP Quick Setup General
9.9
CRITICAL
EPSS
41.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.

CVE-2024-50427
SurveyJS General
9.9
CRITICAL
EPSS
69.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

CVE-2024-20997
Hospitality Simphony Web Database
9.9
CRITICAL
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality,

CVE-2024-4701
Genie General
9.9
CRITICAL
EPSS
17.6%
2024 CWE-22 2 PoCs

A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

CVE-2024-25693
Portal for ArcGIS General
9.9
CRITICAL
EPSS
9.9%
2024 CWE-22 1 PoC

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

CVE-2024-8672
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets Web Windows
9.9
CRITICAL
EPSS
78.2%
2024 CWE-94 1 PoC

The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due to the plugin allowing users to supply input that will be passed through eval() without any filtering or capability checks. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. Special note: We suggested the vendor implement an allowlist of functions and limit the ability

CVE-2024-36393
SysAid Database
9.9
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-31390
Breakdance General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 3 PoCs

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

CVE-2024-9014
pgAdmin 4 General ⚡ nuclei
9.9
CRITICAL
EPSS
92.9%
2024 2 PoCs

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

CVE-2024-42327
Zabbix Web Database
9.9
CRITICAL
EPSS
91.4%
2024 CWE-89 9 PoCs

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVE-2024-31380
Oxygen Builder General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

CVE-2024-31286
WP Photo Album Plus General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

CVE-2024-2044
pgAdmin 4 Windows
9.9
CRITICAL
EPSS
83.5%
2024 1 PoC

pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.

CVE-2024-39930
Software Genérico Networking Windows
9.9
CRITICAL
EPSS
11.9%
2024 4 PoCs

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.

CVE-2024-37288
Kibana Web
9.9
CRITICAL
EPSS
1.9%
2024 CWE-502 2 PoCs

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-security.html  and have configured an Amazon Bedrock connector https://www.elastic.co/guide/en/security/current/assistant-connect-to-bedrock.html .

CVE-2024-3105
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts Web Windows
9.9
CRITICAL
EPSS
57.9%
2024 CWE-94 1 PoC

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.

CVE-2024-33699
WBR-6012 Networking
9.9
CRITICAL
EPSS
7.2%
2024 CWE-620 2 PoCs

The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.