939 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9933
WatchTowerHQ Web Windows
9.8
CRITICAL
EPSS
37.3%
2024 CWE-288 2 PoCs

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user.

CVE-2024-8425
WooCommerce Ultimate Gift Card Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
42.7%
2024 CWE-434 2 PoCs

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added.

CVE-2024-46483
Software Genérico General
9.8
CRITICAL
EPSS
13.9%
2024 1 PoC

Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow with attacker-controlled content.

CVE-2024-3660
keras General
9.8
CRITICAL
EPSS
0.4%
2024 3 PoCs

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

CVE-2024-9707
Hunk Companion Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2024 CWE-862 2 PoCs

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVE-2024-9290
Super Backup & Clone - Migrate for WordPress Web Windows
9.8
CRITICAL
EPSS
67.7%
2024 CWE-434 2 PoCs

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-46532
Software Genérico Web Database
9.8
CRITICAL
EPSS
4.2%
2024 2 PoCs

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

CVE-2024-22751
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

CVE-2024-33789
Software Genérico Web
9.8
CRITICAL
EPSS
9.5%
2024 1 PoC

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

CVE-2024-0799
Unified Data Protection General ⚡ nuclei
9.8
CRITICAL
EPSS
37.9%
2024 CWE-287 1 PoC

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

CVE-2024-38289
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.3%
2024 0 PoCs

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

CVE-2024-12084
Software Genérico General
9.8
CRITICAL
EPSS
3.5%
2024 CWE-122 2 PoCs

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVE-2024-4040
🔥 KEV CrushFTP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-1336 21 PoCs

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CVE-2024-35339
Software Genérico General
9.8
CRITICAL
EPSS
3.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.

CVE-2024-29974
NAS326 firmware Cloud
9.8
CRITICAL
EPSS
47.6%
2024 CWE-434 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.

CVE-2024-48428
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 2 PoCs

An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.

CVE-2024-37084
Spring Cloud Data Flow Web Cloud
9.8
CRITICAL
EPSS
83.3%
2024 5 PoCs

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

CVE-2024-29943
Firefox Web
9.8
CRITICAL
EPSS
53.9%
2024 1 PoC

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

CVE-2024-13804
HPE Insight Cluster Management Utility (CMU) General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

Unauthenticated RCE in HPE Insight Cluster Management Utility

CVE-2024-36042
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.