94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-54449
LogicalDOC Community Web
8.7
HIGH
EPSS
0.2%
2024 CWE-23 1 PoC

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVE-2024-11664
eNMS Networking
8.7
HIGH
EPSS
3.8%
2024 CWE-22 1 PoC

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the file eNMS/controller.py of the component TGZ File Handler. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 22b0b443acca740fc83b5544165c1f53eff3f529. It is recommended to apply a patch to fix this issue.

CVE-2024-12245
LogicalDOC Community Database
8.7
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents. Account takeover is a potential outcome depending on the presence or lack thereof entries in certain database tables.

CVE-2024-58310
Network Management Card 4 Web
8.7
HIGH
EPSS
0.2%
2024 CWE-22 1 PoC

APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like /etc/passwd by using encoded path traversal characters in HTTP requests.

CVE-2024-58288
Genexus Protection Server Windows
8.7
HIGH
EPSS
0.1%
2024 CWE-428 1 PoC

Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations.

CVE-2024-58316
online-shopping-system-advanced Web Database
8.7
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.

CVE-2024-43683
TimeProvider 4100 Web
8.7
HIGH
EPSS
0.2%
2024 CWE-601 1 PoC

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.

CVE-2024-8004
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
0.9%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-58312
xbtitFM Web
8.7
HIGH
EPSS
3.3%
2024 CWE-22 1 PoC

xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.

CVE-2024-58283
WBCE CMS Web
8.7
HIGH
EPSS
0.4%
2024 CWE-434 1 PoC

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.

CVE-2024-5421
utnserver Pro General ⚡ nuclei
8.7
HIGH
EPSS
23.8%
2024 CWE-78 2 PoCs

Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2024-12091
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-7007
Broadcast Signal Processor TRA7005 General
8.7
HIGH
EPSS
0.1%
2024 CWE-288 1 PoC

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

CVE-2024-39777
Mattermost General
8.7
HIGH
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.

CVE-2024-45309
onedev General ⚡ nuclei
8.7
HIGH
EPSS
89.0%
2024 CWE-200 0 PoCs

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.

CVE-2024-26290
Avid NEXIS E-series General
8.7
HIGH
EPSS
0.2%
2024 CWE-20 1 PoC

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before 2024.6.0; Avid NEXIS F-series: before 2024.6.0; Avid NEXIS PRO+: before 2024.6.0; System Director Appliance (SDA+): before 2024.6.0.

CVE-2024-11745
AC8 General
8.7
HIGH
EPSS
0.1%
2024 CWE-121 2 PoCs

A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7333
N350RT General
8.7
HIGH
EPSS
0.4%
2024 CWE-120 1 PoC

A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument week/sTime/eTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273256. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-13991
Cloud Video Platform Cloud
8.7
HIGH
EPSS
0.5%
2024 CWE-22 1 PoC

Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action=downloadBackupFile` endpoint and retrieve files from the server filesystem. VulnCheck has observed this vulnerability being exploited in the wild.

CVE-2024-12090
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.