7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40125
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.

CVE-2024-55507
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

CVE-2024-39914
fogproject Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2024 CWE-77 0 PoCs

FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.

CVE-2024-51978
DCP-J928N-W/B Web ⚡ nuclei
9.8
CRITICAL
EPSS
53.6%
2024 CWE-1391 3 PoCs

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

CVE-2024-6847
Chatbot with ChatGPT WordPress Web Database Windows
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

CVE-2024-52316
Apache Tomcat Web
9.8
CRITICAL
EPSS
2.7%
2024 CWE-391 1 PoC

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The fol

CVE-2024-39250
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
88.4%
2024 1 PoC

EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

CVE-2024-8275
The Events Calendar Web Database Windows
9.8
CRITICAL
EPSS
83.5%
2024 CWE-89 3 PoCs

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.

CVE-2024-54803
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.

CVE-2024-38395
Software Genérico General
9.8
CRITICAL
EPSS
9.2%
2024 1 PoC

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

CVE-2024-33180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

CVE-2024-28395
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

CVE-2024-34945
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.

CVE-2024-28986
🔥 KEV Web Help Desk General ⚡ nuclei
9.8
CRITICAL
EPSS
79.7%
2024 CWE-502 0 PoCs

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

CVE-2024-39205
Software Genérico Web
9.8
CRITICAL
EPSS
83.9%
2024 2 PoCs

An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.

CVE-2024-47926
TCExam Database
9.8
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-40446
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script

CVE-2024-4040
🔥 KEV CrushFTP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-1336 21 PoCs

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CVE-2024-0799
Unified Data Protection General ⚡ nuclei
9.8
CRITICAL
EPSS
37.9%
2024 CWE-287 1 PoC

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

CVE-2024-42919
Software Genérico General
9.8
CRITICAL
EPSS
10.2%
2024 1 PoC

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.