7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6584
Jetpack Boost General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

CVE-2024-10025
SICK CLV6xx General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-798 1 PoC

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.

CVE-2024-2862
LG LED Assistant General ⚡ nuclei
9.1
CRITICAL
EPSS
74.5%
2024 CWE-287 0 PoCs

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

CVE-2024-36104
Apache OFBiz Web ⚡ nuclei
9.1
CRITICAL
EPSS
93.1%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

CVE-2024-37899
xwiki-platform General
9.1
CRITICAL
EPSS
14.1%
2024 CWE-94 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the user profile before getting an admin to disable the user account. To reproduce, as a user without script nor programming rights, edit the about section of your user profile and add `{{groovy}}services.logging.getLogger("attacker").error("Hello from Groovy!"){{/groovy}}`. As an admin, go to the user profile and click the "Disable this account" butto

CVE-2024-40422
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.6%
2024 4 PoCs

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

CVE-2024-54880
Software Genérico Web
9.1
CRITICAL
EPSS
5.5%
2024 2 PoCs

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

CVE-2024-57763
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.

CVE-2024-29868
Apache StreamPipes Web ⚡ nuclei
9.1
CRITICAL
EPSS
78.4%
2024 CWE-338 1 PoC

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

CVE-2024-46627
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
91.7%
2024 1 PoC

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

CVE-2024-56278
WP Ultimate Exporter Web
9.1
CRITICAL
EPSS
49.1%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1.

CVE-2024-32842
EPM Database
9.1
CRITICAL
EPSS
9.1%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-22393
Apache Answer Web
9.1
CRITICAL
EPSS
26.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

CVE-2024-29643
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

CVE-2024-26503
Software Genérico Web
9.1
CRITICAL
EPSS
2.2%
2024 1 PoC

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to certbadge.php endpoint.

CVE-2024-25170
Software Genérico General
9.1
CRITICAL
EPSS
1.8%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

CVE-2024-5975
CZ Loan Management Web Database Windows ⚡ nuclei
9.1
CRITICAL
EPSS
43.9%
2024 1 PoC

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-36394
SysAid General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-7387
Software Genérico DevOps
9.1
CRITICAL
EPSS
0.8%
2024 CWE-250 1 PoC

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

CVE-2024-51063
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.