7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1197
Testimonial Page Manager Web Database
7.3
HIGH
EPSS
0.0%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-252695.

CVE-2024-0648
CMS Web
7.3
HIGH
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The manipulation of the argument templateFile leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251374 is the identifier assigned to this vulnerability.

CVE-2024-50450
MDTF General
7.3
HIGH
EPSS
52.5%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

CVE-2024-57378
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 2 PoCs

Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.

CVE-2024-0683
Bulgarisation for WooCommerce Web Windows
7.3
HIGH
EPSS
26.4%
2024 CWE-862 1 PoC

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and delete labels.

CVE-2024-2577
Employee Task Management System Web
7.3
HIGH
EPSS
0.0%
2024 CWE-639 1 PoC

A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257080.

CVE-2024-0352
Likeshop Web ⚡ nuclei
7.3
HIGH
EPSS
91.9%
2024 CWE-434 1 PoC

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250120.

CVE-2024-0294
LR1200GB General
7.3
HIGH
EPSS
2.1%
2024 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249860. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1302
Monitool General
7.3
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

CVE-2024-1824
House Rental Management System Web Database
7.3
HIGH
EPSS
0.0%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file signing.php. The manipulation of the argument uname/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254612.

CVE-2024-3085
Emergency Ambulance Hiring Portal Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258678 is the identifier assigned to this vulnerability.

CVE-2024-0307
Dynamic Lab Management System Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249874 is the identifier assigned to this vulnerability.

CVE-2024-1820
Crime Reporting System Web Database
7.3
HIGH
EPSS
0.0%
2024 CWE-89 1 PoC

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254608.

CVE-2024-0510
YiQiNiu Web
7.3
HIGH
EPSS
0.2%
2024 CWE-918 1 PoC

A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of the file /application/pay/controller/Api.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250652.

CVE-2024-42471
toolkit General
7.3
HIGH
EPSS
7.7%
2024 CWE-22 1 PoC

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

CVE-2024-3439
Prison Management System Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259692.

CVE-2024-31954
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)

CVE-2024-36683
Software Genérico Database ⚡ nuclei
7.3
HIGH
EPSS
1.0%
2024 0 PoCs

SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via the ProductsAlertAjaxProcessModuleFrontController::initContent method.

CVE-2024-28279
Software Genérico Web Database
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.

CVE-2024-28138
Scan2Net Web
7.3
HIGH
EPSS
1.0%
2024 CWE-78 2 PoCs

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET parameter "data" is not properly sanitized.