7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22416
pyload Web
9.7
CRITICAL
EPSS
5.9%
2024 CWE-352 1 PoC

pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since the session cookie is not set to `SameSite: strict`, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result any API call can be made via a CSRF attack by an unauthenticated user. This issue has been addressed in release `0.5.0b3.dev78`. All users are advised to upgrade.

CVE-2024-34716
PrestaShop Web
9.7
CRITICAL
EPSS
36.7%
2024 CWE-79 4 PoCs

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of t

CVE-2024-38889
Software Genérico Database
9.6
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

CVE-2024-0440
mintplex-labs/anything-llm General
9.6
CRITICAL
EPSS
0.1%
2024 CWE-918 1 PoC

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.

CVE-2024-21762
🔥 KEV FortiProxy Networking
9.6
CRITICAL
EPSS
92.7%
2024 CWE-787 27 PoCs

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

CVE-2024-22718
Software Genérico Web
9.6
CRITICAL
EPSS
0.1%
2024 1 PoC

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

CVE-2024-33857
Software Genérico General
9.6
CRITICAL
EPSS
0.2%
2024 2 PoCs

An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Server Side Request Forgery.

CVE-2024-31650
Software Genérico Web
9.6
CRITICAL
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

CVE-2024-0550
mintplex-labs/anything-llm Web
9.6
CRITICAL
EPSS
0.8%
2024 CWE-23 1 PoC

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.

CVE-2024-9148
FlowiseChatEmbed Web
9.6
CRITICAL
EPSS
1.9%
2024 CWE-79 1 PoC

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

CVE-2024-5655
GitLab DevOps
9.6
CRITICAL
EPSS
1.7%
2024 CWE-284 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVE-2024-7982
Registrations for the Events Calendar Web Windows
9.6
CRITICAL
EPSS
1.9%
2024 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2024-0765
mintplex-labs/anything-llm General
9.6
CRITICAL
EPSS
0.1%
2024 CWE-200 1 PoC

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and read that export that would enable you do exfiltrate data of the system at that save state. This would require the attacked to be granted explicit access to the system, but they can do this at any role. Additionally, post-download, the data is deleted so no evidence would exist that the exfiltration occured.

CVE-2024-52402
Exclusive Content Password Protect Web
9.6
CRITICAL
EPSS
18.1%
2024 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0.

CVE-2024-4947
🔥 KEV Chrome General
9.6
CRITICAL
EPSS
0.3%
2024 2 PoCs

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-28739
Software Genérico General
9.6
CRITICAL
EPSS
23.0%
2024 1 PoC

An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

CVE-2024-12641
TenderDocTransfer Web
9.6
CRITICAL
EPSS
35.7%
2024 CWE-79 1 PoC

TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.

CVE-2024-29824
🔥 KEV EPM Database ⚡ nuclei
9.6
CRITICAL
EPSS
94.0%
2024 3 PoCs

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-23674
Software Genérico General
9.6
CRITICAL
EPSS
0.1%
2024 1 PoC

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the "sPACE (Spoofing Password Authenticated Connection Establishment)" issue. This occurs because of a combination of factors, such as insecure PIN entry (for basic readers) and eid:// deeplinking. The victim must be using a modified eID kernel, which may occur if the victim is tricked in

CVE-2024-55591
🔥 KEV FortiOS General ⚡ nuclei
9.6
CRITICAL
EPSS
94.1%
2024 CWE-288 11 PoCs

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.