4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-36404
geotools General ⚡ nuclei
9.8
CRITICAL
EPSS
90.7%
2024 CWE-95 2 PoCs

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content.

CVE-2024-50476
GRÜN spendino Spendenformular General
9.8
CRITICAL
EPSS
24.7%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

CVE-2024-24029
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

CVE-2024-9932
Wux Blog Editor Web Windows
9.8
CRITICAL
EPSS
75.4%
2024 CWE-434 2 PoCs

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-5488
SEOPress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
71.9%
2024 1 PoC

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

CVE-2024-12356
🔥 KEV Remote Support General
9.8
CRITICAL
EPSS
93.9%
2024 CWE-77 2 PoCs

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

CVE-2024-29276
Software Genérico General
9.8
CRITICAL
EPSS
14.7%
2024 1 PoC

An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.

CVE-2024-22751
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

CVE-2024-53924
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2024 1 PoC

Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.

CVE-2024-35286
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
63.8%
2024 0 PoCs

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

CVE-2024-27143
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
0.2%
2024 CWE-250 2 PoCs

Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts

CVE-2024-52316
Apache Tomcat Web
9.8
CRITICAL
EPSS
2.7%
2024 CWE-391 1 PoC

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The fol

CVE-2024-55507
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

CVE-2024-35374
Software Genérico Web Database
9.8
CRITICAL
EPSS
8.4%
2024 1 PoC

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

CVE-2024-24321
Software Genérico General
9.8
CRITICAL
EPSS
2.2%
2024 1 PoC

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

CVE-2024-22916
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 2 PoCs

In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

CVE-2024-13160
🔥 KEV Endpoint Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-38886
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.

CVE-2024-4040
🔥 KEV CrushFTP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-1336 21 PoCs

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CVE-2024-28222
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.