3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9987
Pandora FMS Database
8.6
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.

CVE-2024-36117
reposilite General ⚡ nuclei
8.6
HIGH
EPSS
74.1%
2024 CWE-22 0 PoCs

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.

CVE-2024-21674
Confluence Data Center General
8.6
HIGH
EPSS
2.5%
2024 2 PoCs

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, no impact to integrity, no impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if

CVE-2024-12992
Pandora FMS General
8.6
HIGH
EPSS
0.6%
2024 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .

CVE-2024-9497
USBXpress 4 SDK General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-58305
WonderCMS Web
8.6
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVE-2024-13726
Themes Coder Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
15.2%
2024 1 PoC

The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-37359
Pentaho Data Integration & Analytics Web Networking
8.6
HIGH
EPSS
0.0%
2024 CWE-918 1 PoC

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not validate the Host header of incoming HTTP/HTTPS requests.   By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the atta

CVE-2024-37818
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2024 1 PoC

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request. NOTE: The Strapi Development Community argues that this issue is not valid. They contend that "the strapi/admin was wrongly attributed a flaw that only pertains to the strapi.io website, and which, at the end of the day, does not pose any real SSRF risk to applications that make use of the Strapi library."

CVE-2024-1061
Software Genérico Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
83.4%
2024 CWE-89 1 PoC

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

CVE-2024-0368
Hustle – Email Marketing, Lead Generation, Optins, Popups Web Windows
8.6
HIGH
EPSS
1.6%
2024 CWE-522 2 PoCs

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.

CVE-2024-58313
xbtitFM Web
8.6
HIGH
EPSS
0.1%
2024 CWE-434 1 PoC

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

CVE-2024-36416
SuiteCRM Web
8.6
HIGH
EPSS
44.7%
2024 CWE-779 1 PoC

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

CVE-2024-35340
Software Genérico General
8.6
HIGH
EPSS
2.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

CVE-2024-9490
Silicon Labs IDE (8-bit) General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-5716
Unified SecOps Platform General
8.6
HIGH
EPSS
0.5%
2024 CWE-307 1 PoC

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password reset mechanism. The issue results from the lack of restriction of excessive authentication attempts. An attacker can leverage this vulnerability to reset a user's password and bypass authentication on the system. Was ZDI-CAN-24164.

CVE-2024-48248
🔥 KEV Backup & Replication Director Networking ⚡ nuclei
8.6
HIGH
EPSS
94.0%
2024 CWE-36 3 PoCs

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

CVE-2024-34361
pi-hole General
8.6
HIGH
EPSS
58.2%
2024 CWE-918 1 PoC

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.

CVE-2024-13206
Antivirus General
8.5
HIGH
EPSS
0.0%
2024 CWE-276 1 PoC

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3301
DELMIA Apriso General
8.5
HIGH
EPSS
9.5%
2024 CWE-502 1 PoC

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.