578 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-51482
zoneminder Web Database ⚡ nuclei
10.0
CRITICAL
EPSS
50.9%
2024 CWE-89 1 PoC

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

CVE-2024-7591
LoadMaster General ⚡ nuclei
10.0
CRITICAL
EPSS
31.5%
2024 CWE-78 1 PoC

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

CVE-2024-22476
Intel(R) Neural Compressor software General ⚡ nuclei
10.0
CRITICAL
EPSS
74.9%
2024 0 PoCs

Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

CVE-2024-3605
WP Hotel Booking Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
81.4%
2024 CWE-89 1 PoC

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-51567
🔥 KEV Software Genérico Database ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 5 PoCs

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

CVE-2024-6886
Gitea Open Source Git Server Web ⚡ nuclei
10.0
CRITICAL
EPSS
25.2%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

CVE-2024-5932
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
94.2%
2024 CWE-502 5 PoCs

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.

CVE-2024-1709
🔥 KEV ScreenConnect General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-288 15 PoCs

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

CVE-2024-46506
NetAlertX Web ⚡ nuclei
10.0
CRITICAL
EPSS
91.5%
2024 CWE-306 1 PoC

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

CVE-2024-51378
🔥 KEV Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 5 PoCs

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

CVE-2024-10081
CodeChecker Web ⚡ nuclei
10.0
CRITICAL
EPSS
73.9%
2024 CWE-288 0 PoCs

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include the ability to add, edit, and remove products, among others. All endpoints, apart from the /Authentication is affected by the vulnerability. This issue affects CodeChecker: through 6.24.1.

CVE-2024-46986
camaleon-cms Web ⚡ nuclei
10.0
CRITICAL
EPSS
92.3%
2024 CWE-74 1 PoC

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the underlying filesystem). E.g. This can lead to a delayed remote code execution in case an attacker is able to write a Ruby file into the config/initializers/ subfolder of the Ruby on Rails application. This issue has been addressed in release version 2.8.2. Users are

CVE-2024-1212
🔥 KEV LoadMaster General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-78 5 PoCs

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CVE-2024-3400
🔥 KEV PAN-OS Networking Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-77 45 PoCs

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

CVE-2024-50498
WP Query Console General ⚡ nuclei
10.0
CRITICAL
EPSS
91.9%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

CVE-2024-7854
Woo Inquiry Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
80.3%
2024 CWE-89 1 PoC

The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-27115
SO Planning General ⚡ nuclei
10.0
CRITICAL
EPSS
81.8%
2024 CWE-434 1 PoC

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.

CVE-2024-21650
xwiki-platform General ⚡ nuclei
10.0
CRITICAL
EPSS
92.5%
2024 CWE-95 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.

CVE-2024-43160
BerqWP General ⚡ nuclei
10.0
CRITICAL
EPSS
83.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

CVE-2024-51568
Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.0%
2024 2 PoCs

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.