3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-4325
gradio-app/gradio Web Cloud ⚡ nuclei
8.6
HIGH
EPSS
65.1%
2024 CWE-918 0 PoCs

A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. The vulnerability arises when the `path` value, obtained from the user and expected to be a URL, is used to make an HTTP request without sufficient validation checks. This flaw allows an attacker to send crafted requests that could lead to unauthorized access to the local network or the AWS metadata endpoint, thereby compromising the security of internal servers.

CVE-2024-41987
Opera Plus FM Family Transmitter Web
8.6
HIGH
EPSS
0.2%
2024 CWE-352 1 PoC

The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

CVE-2024-31851
Sync General ⚡ nuclei
8.6
HIGH
EPSS
89.3%
2024 CWE-22 1 PoC

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

CVE-2024-9496
USBXpress Dev Kit General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-42463
upKeeper Manager General
8.6
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-9499
USBXpress Win 98SE Dev Kit General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-22917
Software Genérico Web Database
8.6
HIGH
EPSS
1.1%
2024 1 PoC

SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

CVE-2024-43357
ecma262 Web
8.6
HIGH
EPSS
0.6%
2024 CWE-248 5 PoCs

ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 spec refactor, may lead to mis-implementation in a way that could present as a security vulnerability, such as type confusion and pointer dereference. The internal async generator machinery calls regular promise resolver functions on IteratorResult (`{ done, value }`) objects that it creates, assuming that the IteratorResult objects will not be then-ables. Unfortunately, these IteratorResult objects inherit from `Obj

CVE-2024-24429
Software Genérico General
8.6
HIGH
EPSS
0.2%
2024 1 PoC

A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

CVE-2024-58282
Serendipity Web
8.6
HIGH
EPSS
0.3%
2024 CWE-434 1 PoC

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server.

CVE-2024-6420
Hide My WP Ghost Web Windows ⚡ nuclei
8.6
HIGH
EPSS
36.9%
2024 1 PoC

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

CVE-2024-58295
ElkArte Forum Web
8.6
HIGH
EPSS
0.6%
2024 CWE-434 1 PoC

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.

CVE-2024-58338
Flamingo XL General
8.6
HIGH
EPSS
0.1%
2024 CWE-78 2 PoCs

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

CVE-2024-48766
NetAlertX Web ⚡ nuclei
8.6
HIGH
EPSS
77.7%
2024 CWE-698 1 PoC

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

CVE-2024-34657
Samsung Notes General
8.6
HIGH
EPSS
3.0%
2024 1 PoC

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

CVE-2024-12542
linkID Web Windows
8.6
HIGH
EPSS
30.4%
2024 CWE-862 2 PoCs

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

CVE-2024-9494
CP210 VCP Win 2k General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-34470
Software Genérico Web ⚡ nuclei
8.6
HIGH
EPSS
93.6%
2024 5 PoCs

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

CVE-2024-9492
Flash Programming Utility General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.