17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-33374
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

CVE-2024-25843
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

CVE-2024-48307
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 1 PoC

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

CVE-2024-21508
mysql2 Database
9.8
CRITICAL
EPSS
46.2%
2024 CWE-94 2 PoCs

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVE-2024-23746
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).

CVE-2024-50588
Elefant General
9.8
CRITICAL
EPSS
0.4%
2024 CWE-1393 2 PoCs

An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM").

CVE-2024-29849
Backup & Replication General
9.8
CRITICAL
EPSS
53.6%
2024 1 PoC

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

CVE-2024-23739
Software Genérico General
9.8
CRITICAL
EPSS
35.8%
2024 2 PoCs

An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-40711
🔥 KEV Backup and Recovery General ⚡ nuclei
9.8
CRITICAL
EPSS
68.2%
2024 4 PoCs

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

CVE-2024-57035
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2024-33434
Software Genérico Networking
9.8
CRITICAL
EPSS
7.6%
2024 1 PoC

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.

CVE-2024-25239
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

CVE-2024-39907
1Panel Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 CWE-89 0 PoCs

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

CVE-2024-51136
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.

CVE-2024-23653
buildkit DevOps Web
9.8
CRITICAL
EPSS
10.3%
2024 CWE-863 1 PoC

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit

CVE-2024-7593
🔥 KEV vTM General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-287 6 PoCs

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

CVE-2024-33078
Software Genérico General
9.8
CRITICAL
EPSS
1.3%
2024 1 PoC

Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.

CVE-2024-38396
Software Genérico General
9.8
CRITICAL
EPSS
10.3%
2024 3 PoCs

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

CVE-2024-54804
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.