94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-50491
RSVP ME Database
9.3
CRITICAL
EPSS
37.7%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

CVE-2024-13979
St. Joe ERP System ("圣乔ERP系统") Web Database ⚡ nuclei
9.3
CRITICAL
EPSS
9.0%
2024 CWE-89 2 PoCs

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundatio

CVE-2024-58307
CSZCMS Web Database
9.3
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

CVE-2024-7395
JetPort 5601v3 General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-287 2 PoCs

An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

CVE-2024-58299
FTP Server General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-121 1 PoC

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

CVE-2024-47073
dataease General ⚡ nuclei
9.3
CRITICAL
EPSS
56.1%
2024 CWE-347 0 PoCs

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-43917
TI WooCommerce Wishlist Database ⚡ nuclei
9.3
CRITICAL
EPSS
90.0%
2024 CWE-89 2 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.

CVE-2024-43144
Cost Calculator Builder Database ⚡ nuclei
9.3
CRITICAL
EPSS
23.2%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVE-2024-57428
Software Genérico Web
9.3
CRITICAL
EPSS
2.0%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.

CVE-2024-42500
HPE HP-UX ONCplus General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

CVE-2024-4879
🔥 KEV Now Platform General ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-1287 12 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-28752
Apache CXF Web ⚡ nuclei
9.3
CRITICAL
EPSS
50.8%
2024 CWE-918 1 PoC

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

CVE-2024-6060
Webscopes Web
9.3
CRITICAL
EPSS
0.1%
2024 CWE-532 1 PoC

An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

CVE-2024-5057
Easy Digital Downloads Database ⚡ nuclei
9.3
CRITICAL
EPSS
64.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

CVE-2024-55978
Code Generator Pro Database
9.3
CRITICAL
EPSS
6.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation Code Generator Pro code-generator-pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through <= 1.2.

CVE-2024-57823
Raptor RDF Syntax Library General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-191 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVE-2024-30502
WP Travel Engine Database ⚡ nuclei
9.3
CRITICAL
EPSS
18.4%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.

CVE-2024-55547
IAP-420 General
9.3
CRITICAL
EPSS
37.2%
2024 CWE-77 2 PoCs

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

CVE-2024-55976
Critical Site Intel Database
9.3
CRITICAL
EPSS
35.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mikeleembruggen Critical Site Intel critical-site-intel-stats allows SQL Injection.This issue affects Critical Site Intel: from n/a through <= 1.0.

CVE-2024-58286
dizqueTV General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-78 1 PoC

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.