783 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-24112
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
81.6%
2024 0 PoCs

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

CVE-2024-1698
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 5 PoCs

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-8856
Backup and Staging by WP Time Capsule Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2024 CWE-434 4 PoCs

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-6670
🔥 KEV WhatsUp Gold Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2024 CWE-89 1 PoC

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CVE-2024-42640
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
88.8%
2024 3 PoCs

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2024-51211
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
4.1%
2024 1 PoC

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

CVE-2024-28255
OpenMetadata Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-287 2 PoCs

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to `GET /api/v1;v1%2fusers%2flo

CVE-2024-45622
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
57.4%
2024 0 PoCs

ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

CVE-2024-27348
🔥 KEV Apache HugeGraph-Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 5 PoCs

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

CVE-2024-3552
Web Directory Free Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 4 PoCs

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 10 PoCs

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-9234
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2024 CWE-862 3 PoCs

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.

CVE-2019-3396
🔥 KEV Confluence Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2019 26 PoCs

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

CVE-2019-25213
Advanced Access Manager – Access Governance for WordPress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
40.2%
2019 CWE-22 0 PoCs

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

CVE-2019-16057
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2019 1 PoC

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

CVE-2019-9874
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
87.6%
2019 0 PoCs

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

CVE-2019-7194
🔥 KEV QNAP NAS devices running Photo Station General ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2019 1 PoC

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7195
🔥 KEV QNAP NAS devices running Photo Station General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2019 1 PoC

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.