7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28736
Software Genérico General
7.1
HIGH
EPSS
1.3%
2024 1 PoC

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

CVE-2024-40787
iOS and iPadOS General
7.1
HIGH
EPSS
0.0%
2024 3 PoCs

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.

CVE-2024-0249
Advanced Schedule Posts Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2024-43971
Sunshine Photo Cart Web ⚡ nuclei
7.1
HIGH
EPSS
9.8%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.5.

CVE-2024-54447
LogicalDOC Community Database
7.1
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents. Account takeover is a potential outcome depending on the presence or lack thereof entries in certain database tables.

CVE-2024-0206
Anti-Malware Engine General
7.1
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files

CVE-2024-39646
Custom 404 Pro Web ⚡ nuclei
7.1
HIGH
EPSS
4.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

CVE-2024-34231
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.

CVE-2024-45178
Software Genérico General
7.1
HIGH
EPSS
1.7%
2024 3 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR syst

CVE-2024-5151
SULly Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13632
WP Extra Fields Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-1983
Simple Ajax Chat Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.

CVE-2024-9284
TL-WR841ND General
7.1
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5422
utnserver Pro Web
7.1
HIGH
EPSS
0.1%
2024 CWE-400 2 PoCs

An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2024-56086
Software Genérico General
7.1
HIGH
EPSS
2.6%
2024 1 PoC

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.

CVE-2024-27168
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
7.1
HIGH
EPSS
0.0%
2024 CWE-798 1 PoC

It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.

CVE-2024-21284
Oracle Banking Liquidity Management Web Database
7.1
HIGH
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).

CVE-2024-40799
iOS and iPadOS General
7.1
HIGH
EPSS
0.0%
2024 4 PoCs

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.

CVE-2024-13056
Dyn Business Panel Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13891
Schedule Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin