7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6912
ProcessPlus Database Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-798 2 PoCs

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-57823
Raptor RDF Syntax Library General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-191 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVE-2024-42008
Software Genérico Web
9.3
CRITICAL
EPSS
51.5%
2024 4 PoCs

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

CVE-2024-6913
ProcessPlus Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-250 2 PoCs

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-0012
🔥 KEV Cloud NGFW Web Networking Cloud ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-306 13 PoCs

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice d

CVE-2024-43144
Cost Calculator Builder Database ⚡ nuclei
9.3
CRITICAL
EPSS
23.2%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVE-2024-7988
ThinManager® ThinServer™ General
9.3
CRITICAL
EPSS
12.6%
2024 CWE-20 1 PoC

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

CVE-2024-8752
WebIQ Windows ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-22 1 PoC

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

CVE-2024-9166
Atemio AM 520 HD Full HD Satellite Receiver General ⚡ nuclei
9.3
CRITICAL
EPSS
3.7%
2024 CWE-78 2 PoCs

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVE-2024-0817
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-77 1 PoC

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

CVE-2024-7395
JetPort 5601v3 General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-287 2 PoCs

An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

CVE-2024-58286
dizqueTV General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-78 1 PoC

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

CVE-2024-58299
FTP Server General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-121 1 PoC

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

CVE-2024-7024
Chrome General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-4879
🔥 KEV Now Platform General ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-1287 12 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-42500
HPE HP-UX ONCplus General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

CVE-2024-55982
Share Buttons – Social Media Database
9.3
CRITICAL
EPSS
31.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.

CVE-2024-50491
RSVP ME Database
9.3
CRITICAL
EPSS
37.7%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

CVE-2024-9464
Expedition Web Networking
9.3
CRITICAL
EPSS
85.3%
2024 CWE-78 3 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-5910
🔥 KEV Expedition Networking ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-306 1 PoC

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.