7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-43144
Cost Calculator Builder Database ⚡ nuclei
9.3
CRITICAL
EPSS
23.2%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVE-2024-58299
FTP Server General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-121 1 PoC

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

CVE-2024-9129
Zend Server General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-134 1 PoC

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

CVE-2024-42008
Software Genérico Web
9.3
CRITICAL
EPSS
51.5%
2024 4 PoCs

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

CVE-2024-0815
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

CVE-2024-30498
CRM Perks Forms Database ⚡ nuclei
9.3
CRITICAL
EPSS
15.0%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

CVE-2024-55988
Navayan CSV Export Database
9.3
CRITICAL
EPSS
32.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.

CVE-2024-9464
Expedition Web Networking
9.3
CRITICAL
EPSS
85.3%
2024 CWE-78 3 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-6913
ProcessPlus Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-250 2 PoCs

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-9166
Atemio AM 520 HD Full HD Satellite Receiver General ⚡ nuclei
9.3
CRITICAL
EPSS
3.7%
2024 CWE-78 2 PoCs

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVE-2024-0817
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-77 1 PoC

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

CVE-2024-57823
Raptor RDF Syntax Library General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-191 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVE-2024-58290
Xhibiter NFT Marketplace Database
9.3
CRITICAL
EPSS
0.0%
2024 CWE-89 1 PoC

Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.

CVE-2024-13990
eScan AV General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-295 3 PoCs

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-the-middle (MitM) attack and substitute malicious update payloads for legitimate ones. The eScan AV client accepted these substituted packages and executed or loaded their components (including sideloaded DLLs and Java/installer payloads), enabling remote code execution on affected systems. MicroWorld eScan confirmed remediation of the update mechanism on 2023

CVE-2024-4879
🔥 KEV Now Platform General ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-1287 12 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-13502
NTC2218, NTC2250, NTC2299 General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion.This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The `commit_multicast` page used to configure multicasts in the modem's web administration interface uses improperly parses incoming data from the request before passing it to an `eval` statement in a bash script. This allows attackers to inject arbitrary shell commands.

CVE-2024-13979
St. Joe ERP System ("圣乔ERP系统") Web Database ⚡ nuclei
9.3
CRITICAL
EPSS
9.0%
2024 CWE-89 2 PoCs

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundatio

CVE-2024-46538
Software Genérico Web
9.3
CRITICAL
EPSS
83.6%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.

CVE-2024-55976
Critical Site Intel Database
9.3
CRITICAL
EPSS
35.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mikeleembruggen Critical Site Intel critical-site-intel-stats allows SQL Injection.This issue affects Critical Site Intel: from n/a through <= 1.0.

CVE-2024-5057
Easy Digital Downloads Database ⚡ nuclei
9.3
CRITICAL
EPSS
64.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.