4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34399
Software Genérico General
9.8
CRITICAL
EPSS
1.9%
2024 1 PoC

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.

CVE-2024-25153
FileCatalyst General
9.8
CRITICAL
EPSS
82.2%
2024 CWE-472 3 PoCs

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

CVE-2024-12647
Satera MF656Cdw General
9.8
CRITICAL
EPSS
0.3%
2024 CWE-787 1 PoC

Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS

CVE-2024-41570
Software Genérico General
9.8
CRITICAL
EPSS
74.1%
2024 4 PoCs

An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.

CVE-2024-10245
Relais 2FA Web Windows
9.8
CRITICAL
EPSS
36.4%
2024 CWE-288 1 PoC

The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This is due to incorrect authentication and capability checking in the 'rl_do_ajax' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVE-2024-48590
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.

CVE-2024-29303
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection

CVE-2024-36678
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2024-33792
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.

CVE-2024-46256
Software Genérico Web
9.8
CRITICAL
EPSS
60.1%
2024 1 PoC

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

CVE-2024-31666
Software Genérico Web
9.8
CRITICAL
EPSS
27.1%
2024 1 PoC

An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.

CVE-2024-54806
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.

CVE-2024-0705
Payment Gateway of Stripe for WooCommerce Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.7%
2024 CWE-89 0 PoCs

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11068
DSL6740C Web Networking
9.8
CRITICAL
EPSS
1.2%
2024 CWE-648 1 PoC

The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

CVE-2024-45167
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 3 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. A certain XmlMessage document causes 100% CPU consumption.

CVE-2024-6809
Simple Video Directory Web Database Windows
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-1301
Monitool Database
9.8
CRITICAL
EPSS
33.2%
2024 CWE-89 1 PoC

SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.

CVE-2024-33266
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.