7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46610
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2024 1 PoC

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

CVE-2024-1764
Server General
7.6
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances

CVE-2024-41630
Software Genérico General
7.6
HIGH
EPSS
2.5%
2024 1 PoC

Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

CVE-2024-33911
School Management Pro Database
7.6
HIGH
EPSS
7.9%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a through 10.3.4.

CVE-2024-5429
Logo Slider Web Windows
7.6
HIGH
EPSS
0.4%
2024 1 PoC

The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-28320
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2024 2 PoCs

Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.

CVE-2024-42464
upKeeper Manager General
7.6
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-3661
DHCP Networking
7.6
HIGH
EPSS
2.9%
2024 CWE-306 4 PoCs

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVE-2024-28434
Software Genérico Web
7.6
HIGH
EPSS
0.2%
2024 1 PoC

The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.

CVE-2024-21689
Bamboo Data Center General
7.6
HIGH
EPSS
37.7%
2024 3 PoCs

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one

CVE-2024-44728
Software Genérico Web
7.6
HIGH
EPSS
0.4%
2024 1 PoC

Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.

CVE-2024-29399
Software Genérico Web
7.6
HIGH
EPSS
5.3%
2024 1 PoC

An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.

CVE-2024-28247
pi-hole General
7.6
HIGH
EPSS
7.1%
2024 CWE-200 1 PoC

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files arbitrarily, and because the application runs from behind, reading files is done as a privileged user.If the URL that is in the list of "Adslists" begins with "file*" it is understood that it is updating from a local file, on the other hand if it does not begin with "file*" depending on the state of the response it does one thing or another. The pr

CVE-2024-22851
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

CVE-2024-24549
Apache Tomcat Web
7.5
HIGH
EPSS
64.4%
2024 CWE-20 2 PoCs

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the

CVE-2024-34351
next.js General ⚡ nuclei
7.5
HIGH
EPSS
92.8%
2024 CWE-918 3 PoCs

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vuln

CVE-2024-29511
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 2 PoCs

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

CVE-2024-2169
RouterOS-TFTP Networking
7.5
HIGH
EPSS
1.6%
2024 2 PoCs

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

CVE-2024-13255
RESTful Web Services Web
7.5
HIGH
EPSS
0.2%
2024 CWE-202 1 PoC

Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.

CVE-2024-4773
Firefox General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.