7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28322
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.

CVE-2024-30982
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

CVE-2024-50648
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

CVE-2024-2865
Quality Management System Database
9.8
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality Management System: through 25032024.

CVE-2024-6611
Firefox Web
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVE-2024-6695
User Profile Builder General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

CVE-2024-38437
DSL-225 General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-288 1 PoC

D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

CVE-2024-21014
Hospitality Simphony Web Database
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-41196
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-2054
Artica Proxy Web
9.8
CRITICAL
EPSS
86.9%
2024 CWE-502 3 PoCs

The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.

CVE-2024-40117
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.

CVE-2024-9933
WatchTowerHQ Web Windows
9.8
CRITICAL
EPSS
37.3%
2024 CWE-288 2 PoCs

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user.

CVE-2024-6220
简数采集器 Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.6%
2024 CWE-434 0 PoCs

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-44349
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2024 2 PoCs

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

CVE-2024-8030
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Web
9.8
CRITICAL
EPSS
38.7%
2024 CWE-502 1 PoC

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up to , and including, 2.0.3. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker or above to delete arbitrary file

CVE-2024-43468
🔥 KEV Microsoft Configuration Manager General
9.8
CRITICAL
EPSS
83.1%
2024 CWE-89 3 PoCs

Microsoft Configuration Manager Remote Code Execution Vulnerability

CVE-2024-12648
Satera MF656Cdw General
9.8
CRITICAL
EPSS
0.3%
2024 CWE-787 1 PoC

Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS

CVE-2024-44411
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

CVE-2024-13159
🔥 KEV Endpoint Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-57031
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.