7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1302
Monitool General
7.3
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

CVE-2024-28279
Software Genérico Web Database
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.

CVE-2024-28138
Scan2Net Web
7.3
HIGH
EPSS
1.0%
2024 CWE-78 2 PoCs

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET parameter "data" is not properly sanitized.

CVE-2024-1009
Employee Management System Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/login.php. The manipulation of the argument txtusername leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252278 is the identifier assigned to this vulnerability.

CVE-2024-0510
YiQiNiu Web
7.3
HIGH
EPSS
0.2%
2024 CWE-918 1 PoC

A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of the file /application/pay/controller/Api.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250652.

CVE-2024-0294
LR1200GB General
7.3
HIGH
EPSS
2.1%
2024 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249860. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1828
Library System Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. Affected is an unknown function of the file Source/librarian/user/teacher/registration.php. The manipulation of the argument email/idno/phone/username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254616.

CVE-2024-3203
c-blosc2 General
7.3
HIGH
EPSS
0.6%
2024 CWE-122 1 PoC

A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-259050 is the identifier assigned to this vulnerability.

CVE-2024-2576
Employee Task Management System Web
7.3
HIGH
EPSS
0.0%
2024 CWE-639 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257079.

CVE-2024-1829
Library System Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file Source/librarian/user/student/registration.php. The manipulation of the argument email/regno/phone/username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254617 was assigned to this vulnerability.

CVE-2024-45492
Software Genérico General
7.3
HIGH
EPSS
2.3%
2024 2 PoCs

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2024-4582
GM8181 General
7.3
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP Service. The manipulation of the argument ntp_srv leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-263304.

CVE-2024-21409
Microsoft Visual Studio 2022 version 17.9 General
7.3
HIGH
EPSS
51.3%
2024 CWE-416 1 PoC

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

CVE-2024-56924
Software Genérico Web
7.3
HIGH
EPSS
0.1%
2024 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.

CVE-2024-3088
Emergency Ambulance Hiring Portal Web Database
7.3
HIGH
EPSS
0.0%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This affects an unknown part of the file /admin/forgot-password.php of the component Forgot Password Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258681 was assigned to this vulnerability.

CVE-2024-34581
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.

CVE-2024-40507
Software Genérico General
7.3
HIGH
EPSS
7.8%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

CVE-2024-10958
WP Photo Album Plus Web Windows
7.3
HIGH
EPSS
55.7%
2024 CWE-94 1 PoC

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-13966
BioTime General
7.3
HIGH
EPSS
0.6%
2024 CWE-1393 1 PoC

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").

CVE-2024-0480
Taokeyun Web Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in Taokeyun up to 1.0.5. It has been declared as critical. Affected by this vulnerability is the function index of the file application/index/controller/m/Drs.php of the component HTTP POST Request Handler. The manipulation of the argument cid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250585 was assigned to this vulnerability.