94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34779
EPM Database
9.1
CRITICAL
EPSS
32.9%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-27448
Software Genérico General
9.1
CRITICAL
EPSS
13.0%
2024 1 PoC

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

CVE-2024-40898
Apache HTTP Server Web Windows
9.1
CRITICAL
EPSS
0.7%
2024 CWE-918 4 PoCs

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

CVE-2024-7385
WP Simple HTML Sitemap Web Database Windows
9.1
CRITICAL
EPSS
13.1%
2024 CWE-89 1 PoC

The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-5973
MasterStudy LMS WordPress Plugin Web Windows
9.1
CRITICAL
EPSS
0.9%
2024 1 PoC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVE-2024-36497
WINSelect (Standard + Enterprise) General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-312 2 PoCs

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

CVE-2024-37770
Software Genérico General
9.1
CRITICAL
EPSS
11.0%
2024 1 PoC

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CVE-2024-37388
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

CVE-2024-33610
Multiple MFPs (multifunction printers) General ⚡ nuclei
9.1
CRITICAL
EPSS
62.3%
2024 CWE-288 3 PoCs

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-40896
libxml2 General
9.1
CRITICAL
EPSS
0.6%
2024 CWE-611 1 PoC

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVE-2024-40457
Software Genérico General
9.1
CRITICAL
EPSS
3.0%
2024 1 PoC

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

CVE-2024-38736
Realtyna Organic IDX plugin General
9.1
CRITICAL
EPSS
1.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.

CVE-2024-26517
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

CVE-2024-32840
EPM Database
9.1
CRITICAL
EPSS
32.9%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-25641
cacti Web
9.1
CRITICAL
EPSS
88.1%
2024 CWE-20 7 PoCs

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences a

CVE-2024-45337
golang.org/x/crypto/ssh Networking
9.1
CRITICAL
EPSS
30.3%
2024 3 PoCs

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used t

CVE-2024-2472
LatePoint Plugin Web Windows
9.1
CRITICAL
EPSS
1.8%
2024 CWE-639 1 PoC

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.

CVE-2024-48905
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

CVE-2024-5806
MOVEit Transfer General
9.1
CRITICAL
EPSS
89.9%
2024 CWE-287 2 PoCs

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVE-2024-54879
Software Genérico Web
9.1
CRITICAL
EPSS
4.3%
2024 2 PoCs

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.