939 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22901
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

CVE-2024-6624
JSON API User Web Windows
9.8
CRITICAL
EPSS
43.5%
2024 CWE-269 2 PoCs

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

CVE-2024-30998
Software Genérico Web Database
9.8
CRITICAL
EPSS
13.3%
2024 1 PoC

SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.

CVE-2024-42919
Software Genérico General
9.8
CRITICAL
EPSS
10.2%
2024 1 PoC

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

CVE-2024-28395
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

CVE-2024-39205
Software Genérico Web
9.8
CRITICAL
EPSS
83.9%
2024 2 PoCs

An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.

CVE-2024-6164
Filter & Grids Web Windows
9.8
CRITICAL
EPSS
5.3%
2024 1 PoC

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-22632
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.

CVE-2024-38140
Windows 10 Version 1809 Windows
9.8
CRITICAL
EPSS
5.0%
2024 CWE-416 1 PoC

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

CVE-2024-57049
Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
34.6%
2024 1 PoC

A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. NOTE: this is disputed by the Supplier because the response to the API call is only "non-sensitive UI initialization variables."

CVE-2024-24882
Masteriyo - LMS General ⚡ nuclei
9.8
CRITICAL
EPSS
48.3%
2024 CWE-266 0 PoCs

Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

CVE-2024-29972
NAS326 firmware Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2024 CWE-78 4 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVE-2024-12847
DGN1000 Web
9.8
CRITICAL
EPSS
73.4%
2024 CWE-78 2 PoCs

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.

CVE-2024-48904
Trend Micro Cloud Edge Cloud
9.8
CRITICAL
EPSS
7.2%
2024 2 PoCs

An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.

CVE-2024-24098
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

CVE-2024-44659
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

CVE-2024-41198
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-54363
Wp NssUser Register General
9.8
CRITICAL
EPSS
38.2%
2024 CWE-266 2 PoCs

Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.

CVE-2024-57328
Software Genérico Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.