4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-54676
Apache OpenMeetings Web
9.8
CRITICAL
EPSS
6.1%
2024 CWE-502 1 PoC

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.

CVE-2024-4883
WhatsUp Gold Web
9.8
CRITICAL
EPSS
92.2%
2024 CWE-77 1 PoC

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

CVE-2024-25180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 4 PoCs

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.

CVE-2024-30982
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

CVE-2024-10508
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Web Windows
9.8
CRITICAL
EPSS
15.3%
2024 CWE-230 3 PoCs

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.

CVE-2024-32640
MasaCMS Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 6 PoCs

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

CVE-2024-6396
aimhubio/aim General ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2024 CWE-29 0 PoCs

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.

CVE-2024-25249
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2024 1 PoC

An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-40117
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.

CVE-2024-28713
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

CVE-2024-13011
WP Foodbakery Web Windows
9.8
CRITICAL
EPSS
2.3%
2024 CWE-434 1 PoC

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-3847
Chrome General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-9106
Wechat Social login 微信QQ钉钉登录插件 Web Windows
9.8
CRITICAL
EPSS
41.2%
2024 CWE-288 1 PoC

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

CVE-2024-22857
Software Genérico General
9.8
CRITICAL
EPSS
4.3%
2024 1 PoC

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rule_new() while copying the record_name from file_path + 1 which caused the buffer overflow. An attacker can exploit this vulnerability to overwrite the zlog_record_fn record_func function pointer to get arbitrary code execution or potentially cause remote code execution (RCE).

CVE-2024-35515
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.

CVE-2024-46532
Software Genérico Web Database
9.8
CRITICAL
EPSS
4.2%
2024 2 PoCs

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

CVE-2024-24421
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-12155
SV100 Companion Web Windows
9.8
CRITICAL
EPSS
5.6%
2024 CWE-862 1 PoC

The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function in all versions up to, and including, 2.0.02. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. CVE-2024-54229 may be a duplicate of this issue.

CVE-2024-33485
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component

CVE-2024-25833
Software Genérico Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.