7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5084
Hash Form – Drag & Drop Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2024 CWE-434 7 PoCs

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-23705
Android General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-12209
WP Umbrella: Update Backup Restore & Monitoring Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
89.8%
2024 CWE-98 2 PoCs

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-27144
Toshiba Tec e-Studio multi-function peripheral (MFP) General
9.8
CRITICAL
EPSS
1.6%
2024 CWE-22 2 PoCs

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vul

CVE-2024-21534
jsonpath-plus Web
9.8
CRITICAL
EPSS
92.7%
2024 CWE-94 5 PoCs

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVE-2024-27145
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
0.3%
2024 CWE-22 2 PoCs

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions

CVE-2024-3408
man-group/dtale General ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2024 CWE-798 0 PoCs

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint, even when `enable_custom_filters` is not enabled. This vulnerability allows attackers to bypass aut

CVE-2024-3660
keras General
9.8
CRITICAL
EPSS
0.4%
2024 3 PoCs

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

CVE-2024-36526
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

CVE-2024-42850
Software Genérico General
9.8
CRITICAL
EPSS
49.8%
2024 1 PoC

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

CVE-2024-9441
eMerge e3-Series Web
9.8
CRITICAL
EPSS
60.1%
2024 CWE-78 5 PoCs

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

CVE-2024-22901
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

CVE-2024-21082
BI Publisher (formerly XML Publisher) Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-25254
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

CVE-2024-42393
Hpe Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-3136
MasterStudy LMS WordPress Plugin – for Online Courses and Education Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
54.2%
2024 CWE-98 1 PoC

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-6611
Firefox Web
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVE-2024-54808
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.

CVE-2024-2876
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2024 CWE-89 7 PoCs

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-22611
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.