3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40510
Software Genérico General
8.2
HIGH
EPSS
9.2%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.

CVE-2024-4856
FS Product Inquiry Web Windows
8.2
HIGH
EPSS
1.7%
2024 1 PoC

The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

CVE-2024-21095
Primavera P6 Enterprise Project Portfolio Management Web Database
8.2
HIGH
EPSS
0.2%
2024 1 PoC

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 19.12.0-19.12.22, 20.12.0-20.12.21, 21.12.0-21.12.18, 22.12.0-22.12.12 and 23.12.0-23.12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portf

CVE-2024-35199
serve DevOps Web
8.2
HIGH
EPSS
0.1%
2024 CWE-668 1 PoC

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. Customers using PyTorch inference Deep Learning Containers (DLC) through Amazon SageMaker and EKS are not affected. This issue in TorchServe has been fixed in PR #3083. TorchServe release 0.11.0 includes the fix to address this vulnerability. Users are advised to upgrade. There are no known workarounds

CVE-2024-40348
Software Genérico Web ⚡ nuclei
8.2
HIGH
EPSS
93.4%
2024 2 PoCs

An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

CVE-2024-24947
P3-550E General
8.2
HIGH
EPSS
0.5%
2024 CWE-787 1 PoC

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap corruption that occurs at offset `0xb68c4` of version 1.2.10.9 of the P3-550E firmware, which occurs when a call to `memset` relies on an attacker-controlled length value and corrupts any trailing heap allocations.

CVE-2024-0213
Trellix Agent (TA) General
8.2
HIGH
EPSS
0.1%
2024 CWE-120 1 PoC

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly.

CVE-2024-8977
GitLab DevOps
8.2
HIGH
EPSS
0.1%
2024 CWE-918 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

CVE-2024-43965
SendGrid for WordPress Web Database Windows ⚡ nuclei
8.2
HIGH
EPSS
18.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.

CVE-2024-9466
Expedition Web Networking
8.2
HIGH
EPSS
20.1%
2024 CWE-532 2 PoCs

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.

CVE-2024-42336
Servision IVG Webmax 1.0.57 General
8.2
HIGH
EPSS
0.3%
2024 CWE-287 1 PoC

Servision - CWE-287: Improper Authentication

CVE-2024-21524
node-stringbuilder General
8.2
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative indexes, leading to an Information Disclosure.

CVE-2024-36792
Software Genérico Networking
8.2
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

CVE-2024-21527
github.com/gotenberg/gotenberg/v8/pkg/gotenberg General
8.2
HIGH
EPSS
0.2%
2024 CWE-918 3 PoCs

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when a request is made to a file via localhost, such as <iframe src="\\localhost/etc/passwd">. By exploiting this vulnerability, an attacker can achieve local file inclusion, allowing of sensitive files read on the host system. Workaround An al

CVE-2024-20337
Cisco Secure Client Networking
8.2
HIGH
EPSS
3.6%
2024 CWE-93 1 PoC

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could the

CVE-2024-5736
AdmirorFrames Web
8.2
HIGH
EPSS
28.8%
2024 CWE-918 1 PoC

Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.

CVE-2024-53704
🔥 KEV SonicOS Networking ⚡ nuclei
8.2
HIGH
EPSS
93.9%
2024 CWE-287 1 PoC

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVE-2024-37742
Software Genérico Windows
8.2
HIGH
EPSS
0.5%
2024 4 PoCs

Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams.

CVE-2024-33303
Software Genérico Web
8.2
HIGH
EPSS
0.2%
2024 1 PoC

SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

CVE-2024-21893
🔥 KEV ICS General ⚡ nuclei
8.2
HIGH
EPSS
94.3%
2024 2 PoCs

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.