7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6028
Quiz Maker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2024 CWE-89 2 PoCs

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-34982
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
80.4%
2024 0 PoCs

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-32370
Software Genérico Web
9.8
CRITICAL
EPSS
3.5%
2024 1 PoC

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.

CVE-2024-5084
Hash Form – Drag & Drop Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2024 CWE-434 7 PoCs

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-31705
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2024 2 PoCs

An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

CVE-2024-11704
Firefox General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

CVE-2024-11972
Hunk Companion Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2024 5 PoCs

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

CVE-2024-33789
Software Genérico Web
9.8
CRITICAL
EPSS
9.5%
2024 1 PoC

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

CVE-2024-27304
pgx Database
9.8
CRITICAL
EPSS
1.9%
2024 CWE-89 2 PoCs

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVE-2024-30985
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

CVE-2024-3660
keras General
9.8
CRITICAL
EPSS
0.4%
2024 3 PoCs

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

CVE-2024-25830
Software Genérico General
9.8
CRITICAL
EPSS
39.1%
2024 1 PoC

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

CVE-2024-24724
Software Genérico Web
9.8
CRITICAL
EPSS
45.0%
2024 1 PoC

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

CVE-2024-6164
Filter & Grids Web Windows
9.8
CRITICAL
EPSS
5.3%
2024 1 PoC

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-40782
Safari General
9.8
CRITICAL
EPSS
0.5%
2024 4 PoCs

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2024-6057
Remote Desktop Manager General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.

CVE-2024-23761
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

CVE-2024-41593
Software Genérico General
9.8
CRITICAL
EPSS
7.7%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.

CVE-2024-57032
Software Genérico Web
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.