17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34102
🔥 KEV Adobe Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-611 29 PoCs

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

CVE-2024-22988
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.

CVE-2024-33180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

CVE-2024-1981
Migration, Backup, Staging – WPvivid Web Database Windows
9.8
CRITICAL
EPSS
2.6%
2024 1 PoC

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6057
Remote Desktop Manager General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.

CVE-2024-40782
Safari General
9.8
CRITICAL
EPSS
0.5%
2024 4 PoCs

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2024-53591
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

CVE-2024-27174
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
6.2%
2024 CWE-22 2 PoCs

Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-54807
Software Genérico Networking
9.8
CRITICAL
EPSS
1.9%
2024 1 PoC

In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.

CVE-2024-40110
Software Genérico Web
9.8
CRITICAL
EPSS
32.2%
2024 2 PoCs

Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.

CVE-2024-48050
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.

CVE-2024-50477
Stacks Mobile App Builder General ⚡ nuclei
9.8
CRITICAL
EPSS
82.2%
2024 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

CVE-2024-27746
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.

CVE-2024-25830
Software Genérico General
9.8
CRITICAL
EPSS
39.1%
2024 1 PoC

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

CVE-2024-33215
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

CVE-2024-50766
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

CVE-2024-22852
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVE-2024-8353
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.6%
2024 CWE-502 3 PoCs

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows th

CVE-2024-51051
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.

CVE-2024-30980
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 2 PoCs

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.