7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-24576
rust Web Windows
10.0
CRITICAL
EPSS
80.5%
2024 CWE-78 10 PoCs

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. An attacker able to control the arguments passed to the spawned process could execute arbitrary shell commands by bypassing the escaping. The severity of this vulnerability is critical for those who invoke batch files on Windows with untrusted arguments. No other platform or use is affected. The `Command::arg` and `Command::args` APIs st

CVE-2024-0520
mlflow/mlflow Web
10.0
CRITICAL
EPSS
4.9%
2024 CWE-22 1 PoC

A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a source URL with an HTTP scheme, the filename extracted from the `Content-Disposition` header or the URL path is used to generate the final file path without proper sanitization. This flaw enables an attacker to control the file path fully by utilizing path traversal or absolute path techniques, such as '../../tmp/poc.txt' o

CVE-2024-25600
Bricks Builder General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 CWE-94 22 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

CVE-2024-47875
DOMPurify Web
10.0
CRITICAL
EPSS
0.7%
2024 CWE-79 2 PoCs

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVE-2024-31982
xwiki-platform General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-95 7 PoCs

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. This impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may manually apply the patch to the page `

CVE-2024-1403
OpenEdge General
10.0
CRITICAL
EPSS
16.2%
2024 CWE-305 1 PoC

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  

CVE-2024-20419
Cisco Smart Software Manager On-Prem Web Networking ⚡ nuclei
10.0
CRITICAL
EPSS
91.4%
2024 CWE-620 2 PoCs

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.

CVE-2024-36388
DeviceHub General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-305 1 PoC

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

CVE-2024-49668
Verbalize WP General
10.0
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0.

CVE-2024-3922
Dokan Pro Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
89.7%
2024 CWE-89 1 PoC

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-38366
CocoaPods Networking
10.0
CRITICAL
EPSS
58.5%
2024 CWE-74 1 PoC

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on signup used a rfc-822 library which executes a shell command to validate the email domain MX records validity. It works via an DNS MX. This lookup could be manipulated to also execute a command on the trunk server, effectively giving root access to the server and the infrastructure. This issue was patched server-side with commit 001cc3a430e75a16307f5fd6cdff1363ad2f40f3 in September 2023. This RCE triggered a full user-session reset,

CVE-2024-42462
upKeeper Manager General
10.0
CRITICAL
EPSS
0.1%
2024 CWE-306 1 PoC

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-36412
SuiteCRM Database ⚡ nuclei
10.0
CRITICAL
EPSS
93.6%
2024 CWE-89 0 PoCs

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

CVE-2024-52380
Picsmize General
10.0
CRITICAL
EPSS
60.4%
2024 CWE-434 3 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from n/a through <= 1.0.0.

CVE-2024-32651
changedetection.io General ⚡ nuclei
10.0
CRITICAL
EPSS
92.3%
2024 CWE-1336 3 PoCs

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

CVE-2024-29895
cacti DevOps Web ⚡ nuclei
10.0
CRITICAL
EPSS
93.2%
2024 CWE-77 4 PoCs

Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c

CVE-2024-8522
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
88.1%
2024 CWE-89 2 PoCs

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-2389
Flowmon General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-78 1 PoC

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

CVE-2024-45519
🔥 KEV Software Genérico General
10.0
CRITICAL
EPSS
94.2%
2024 7 PoCs

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

CVE-2024-27972
WP Fusion Lite General
9.9
CRITICAL
EPSS
38.2%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.