17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-51211
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
4.1%
2024 1 PoC

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

CVE-2024-28255
OpenMetadata Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-287 2 PoCs

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to `GET /api/v1;v1%2fusers%2flo

CVE-2024-28394
Software Genérico General
9.8
CRITICAL
EPSS
2.0%
2024 1 PoC

An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.

CVE-2024-35056
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.

CVE-2024-45622
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
57.4%
2024 0 PoCs

ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

CVE-2024-54383
WooCommerce PDF Vouchers General
9.8
CRITICAL
EPSS
7.1%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.

CVE-2024-35469
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2024 2 PoCs

A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

CVE-2024-50944
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 1 PoC

Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.

CVE-2024-27348
🔥 KEV Apache HugeGraph-Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 5 PoCs

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

CVE-2024-21410
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
9.8
CRITICAL
EPSS
5.5%
2024 CWE-287 2 PoCs

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2024-56059
Partners General
9.8
CRITICAL
EPSS
32.3%
2024 CWE-1321 1 PoC

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.

CVE-2024-45265
Software Genérico Web Database
9.8
CRITICAL
EPSS
17.6%
2024 1 PoC

A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

CVE-2024-3552
Web Directory Free Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 4 PoCs

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 10 PoCs

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-9234
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2024 CWE-862 3 PoCs

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.

CVE-2024-31777
Software Genérico Web
9.8
CRITICAL
EPSS
30.4%
2024 1 PoC

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

CVE-2024-36681
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.

CVE-2024-44410
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

CVE-2024-22922
Software Genérico Web
9.8
CRITICAL
EPSS
0.9%
2024 2 PoCs

An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php

CVE-2024-25169
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.