7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-32002
git General
9.1
CRITICAL
EPSS
79.6%
2024 CWE-22 62 PoCs

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is dis

CVE-2024-40583
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

CVE-2024-34779
EPM Database
9.1
CRITICAL
EPSS
32.9%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-54794
Software Genérico General
9.1
CRITICAL
EPSS
2.2%
2024 2 PoCs

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

CVE-2024-25170
Software Genérico General
9.1
CRITICAL
EPSS
1.8%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

CVE-2024-56278
WP Ultimate Exporter Web
9.1
CRITICAL
EPSS
49.1%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1.

CVE-2024-35244
Multiple MFPs (multifunction printers) General
9.1
CRITICAL
EPSS
0.2%
2024 CWE-798 3 PoCs

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-25846
Software Genérico Web
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.

CVE-2024-2862
LG LED Assistant General ⚡ nuclei
9.1
CRITICAL
EPSS
74.5%
2024 CWE-287 0 PoCs

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

CVE-2024-53900
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
52.2%
2024 2 PoCs

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-10004
Firefox for iOS Web
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.

CVE-2024-11042
invoke-ai/invokeai Web Networking Database
9.1
CRITICAL
EPSS
0.9%
2024 CWE-73 1 PoC

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.

CVE-2024-46310
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
83.0%
2024 2 PoCs

Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint

CVE-2024-51063
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

CVE-2024-25413
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVE-2024-45163
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 4 PoCs

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.

CVE-2024-55496
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.

CVE-2024-54507
iOS and iPadOS General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory.

CVE-2024-37899
xwiki-platform General
9.1
CRITICAL
EPSS
14.1%
2024 CWE-94 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the user profile before getting an admin to disable the user account. To reproduce, as a user without script nor programming rights, edit the about section of your user profile and add `{{groovy}}services.logging.getLogger("attacker").error("Hello from Groovy!"){{/groovy}}`. As an admin, go to the user profile and click the "Disable this account" butto

CVE-2024-51747
kanboard Database
9.1
CRITICAL
EPSS
1.4%
2024 CWE-22 1 PoC

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, can set arbitrary file links, by abusing path traversals. Once the modified db is uploaded and the project page is accessed, a file download can be triggered and all files, readable in the context of the Kanbo