939 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-4399
cas General ⚡ nuclei
9.1
CRITICAL
EPSS
25.0%
2024 1 PoC

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

CVE-2024-36497
WINSelect (Standard + Enterprise) General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-312 2 PoCs

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

CVE-2024-22120
Zabbix Database
9.1
CRITICAL
EPSS
92.1%
2024 CWE-20 3 PoCs

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CVE-2024-36840
Software Genérico Web Database
9.1
CRITICAL
EPSS
11.6%
2024 4 PoCs

SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.

CVE-2024-37770
Software Genérico General
9.1
CRITICAL
EPSS
11.0%
2024 1 PoC

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CVE-2024-42049
Software Genérico Windows
9.1
CRITICAL
EPSS
5.8%
2024 1 PoC

TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

CVE-2024-37388
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

CVE-2024-22393
Apache Answer Web
9.1
CRITICAL
EPSS
26.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

CVE-2024-33610
Multiple MFPs (multifunction printers) General ⚡ nuclei
9.1
CRITICAL
EPSS
62.3%
2024 CWE-288 3 PoCs

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-40896
libxml2 General
9.1
CRITICAL
EPSS
0.6%
2024 CWE-611 1 PoC

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVE-2024-40457
Software Genérico General
9.1
CRITICAL
EPSS
3.0%
2024 1 PoC

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

CVE-2024-51747
kanboard Database
9.1
CRITICAL
EPSS
1.4%
2024 CWE-22 1 PoC

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, can set arbitrary file links, by abusing path traversals. Once the modified db is uploaded and the project page is accessed, a file download can be triggered and all files, readable in the context of the Kanbo

CVE-2024-38736
Realtyna Organic IDX plugin General
9.1
CRITICAL
EPSS
1.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.

CVE-2024-48941
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.

CVE-2024-26517
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

CVE-2024-42885
Software Genérico Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.

CVE-2024-32840
EPM Database
9.1
CRITICAL
EPSS
32.9%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-5975
CZ Loan Management Web Database Windows ⚡ nuclei
9.1
CRITICAL
EPSS
43.9%
2024 1 PoC

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-25641
cacti Web
9.1
CRITICAL
EPSS
88.1%
2024 CWE-20 7 PoCs

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences a

CVE-2024-20720
Adobe Commerce General
9.1
CRITICAL
EPSS
7.2%
2024 CWE-78 1 PoC

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.