3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-48208
Software Genérico General
8.6
HIGH
EPSS
38.6%
2024 1 PoC

pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

CVE-2024-58279
appRain CMF Web
8.6
HIGH
EPSS
0.4%
2024 CWE-434 1 PoC

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.

CVE-2024-12535
Host PHP Info Web Windows
8.6
HIGH
EPSS
15.6%
2024 CWE-862 1 PoC

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

CVE-2024-31850
Arc General ⚡ nuclei
8.6
HIGH
EPSS
89.9%
2024 CWE-22 1 PoC

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

CVE-2024-21626
runc DevOps
8.6
HIGH
EPSS
5.5%
2024 CWE-403 17 PoCs

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwr

CVE-2024-21542
luigi General
8.6
HIGH
EPSS
14.2%
2024 CWE-29 2 PoCs

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.

CVE-2024-21632
omniauth-microsoft_graph Web
8.6
HIGH
EPSS
0.3%
2024 CWE-287 1 PoC

omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth misconfiguration in cases when the `email` is used as a trusted user identifier. This could lead to account takeover. Version 2.0.0 contains a fix for this issue.

CVE-2024-41662
vnote Web Networking
8.6
HIGH
EPSS
12.2%
2024 CWE-79 1 PoC

VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary JavaScript code through which remote code execution can be achieved. A patch for this issue is available at commit f1af78573a0ef51d6ef6a0bc4080cddc8f30a545. Other mitigation strategies include implementing rigorous input sanitization for all Markdown content and utilizing a secure Markdown parser that appropriately escapes or st

CVE-2024-21544
spatie/browsershot General
8.6
HIGH
EPSS
0.2%
2024 CWE-20 1 PoC

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.

CVE-2024-39713
Rocket.Chat General ⚡ nuclei
8.6
HIGH
EPSS
89.5%
2024 1 PoC

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

CVE-2024-21136
Retail Xstore Office Web Database ⚡ nuclei
8.6
HIGH
EPSS
42.1%
2024 0 PoCs

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xsto

CVE-2024-57609
Software Genérico General
8.6
HIGH
EPSS
9.5%
2024 3 PoCs

An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.

CVE-2024-20353
🔥 KEV Cisco Adaptive Security Appliance (ASA) Software Web Networking
8.6
HIGH
EPSS
19.5%
2024 CWE-835 2 PoCs

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

CVE-2024-58303
FriendsofFlarum Pretty Mail General
8.6
HIGH
EPSS
0.0%
2024 CWE-1336 1 PoC

FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.

CVE-2024-27453
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2024 1 PoC

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

CVE-2024-24919
🔥 KEV Check Point Quantum Gateway, Spark Gateway and CloudGuard Network Networking Cloud ⚡ nuclei
8.6
HIGH
EPSS
94.3%
2024 CWE-200 67 PoCs

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

CVE-2024-57767
Software Genérico General
8.6
HIGH
EPSS
0.3%
2024 1 PoC

MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.

CVE-2024-50509
Woocommerce Product Design General
8.6
HIGH
EPSS
28.6%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

CVE-2024-1019
ModSecurity General
8.6
HIGH
EPSS
0.3%
2024 CWE-20 1 PoC

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators an

CVE-2024-47076
libcupsfilters General
8.6
HIGH
EPSS
73.9%
2024 CWE-20 1 PoC

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.