7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40442
Software Genérico General
7.2
HIGH
EPSS
0.5%
2024 1 PoC

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.

CVE-2024-24139
Software Genérico Database
7.2
HIGH
EPSS
7.5%
2024 1 PoC

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

CVE-2024-8190
🔥 KEV CSA (Cloud Services Appliance) Cloud
7.2
HIGH
EPSS
91.4%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

CVE-2024-36694
Software Genérico General
7.2
HIGH
EPSS
1.0%
2024 2 PoCs

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

CVE-2024-24899
aops-zeus Web
7.2
HIGH
EPSS
0.3%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py. This issue affects aops-zeus: from 1.2.0 through 1.4.0.

CVE-2024-9831
Taskbuilder Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-40101
Software Genérico Web
7.2
HIGH
EPSS
1.1%
2024 1 PoC

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

CVE-2024-48245
Software Genérico Web Database
7.2
HIGH
EPSS
3.4%
2024 1 PoC

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php.

CVE-2024-22107
Software Genérico Web
7.2
HIGH
EPSS
1.8%
2024 2 PoCs

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.

CVE-2024-5807
Business Card Web Windows
7.2
HIGH
EPSS
0.7%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.

CVE-2024-5902
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Web Windows
7.2
HIGH
EPSS
3.5%
2024 CWE-79 1 PoC

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in feedback form responses that will execute whenever a high-privileged user tries to view them.

CVE-2024-38288
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
68.5%
2024 0 PoCs

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

CVE-2024-8349
Uncanny Groups for LearnDash Web Windows
7.2
HIGH
EPSS
4.0%
2024 CWE-862 1 PoC

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

CVE-2024-6486
ImageMagick Engine Web Windows
7.2
HIGH
EPSS
3.5%
2024 1 PoC

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

CVE-2024-5672
mbNET.mini General
7.2
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

CVE-2024-23112
FortiOS Networking
7.2
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.

CVE-2024-0200
Enterprise Server General ⚡ nuclei
7.2
HIGH
EPSS
70.8%
2024 CWE-470 1 PoC

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2024-1001
N200RE General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-27775
SysAid Windows
7.2
HIGH
EPSS
0.1%
2024 CWE-918 1 PoC

SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash

CVE-2024-0566
Smart Manager Web Database Windows
7.2
HIGH
EPSS
2.5%
2024 2 PoCs

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.