7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28805
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

CVE-2024-4180
The Events Calendar Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
42.4%
2024 1 PoC

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

CVE-2024-31345
Auto Poster General
9.1
CRITICAL
EPSS
1.3%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

CVE-2024-40422
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.6%
2024 4 PoCs

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

CVE-2024-36248
Multiple MFPs (multifunction printers) Web Cloud
9.1
CRITICAL
EPSS
0.2%
2024 CWE-798 3 PoCs

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-53900
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
52.2%
2024 2 PoCs

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-32843
EPM Database
9.1
CRITICAL
EPSS
9.1%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-35293
Series 700 General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-306 2 PoCs

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.

CVE-2024-32167
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVE-2024-37310
everest-core General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-122 1 PoC

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.

CVE-2024-54369
Zita Site Builder General
9.1
CRITICAL
EPSS
19.3%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

CVE-2024-10025
SICK CLV6xx General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-798 1 PoC

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.

CVE-2024-57971
KNOWAGE Web
9.1
CRITICAL
EPSS
0.0%
2024 CWE-99 1 PoC

DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.

CVE-2024-32002
git General
9.1
CRITICAL
EPSS
79.6%
2024 CWE-22 62 PoCs

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is dis

CVE-2024-34451
Software Genérico General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

CVE-2024-57766
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

CVE-2024-21400
Azure Kubernetes Service DevOps Cloud
9.0
CRITICAL
EPSS
1.6%
2024 CWE-22 1 PoC

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVE-2024-32964
lobe-chat Web ⚡ nuclei
9.0
CRITICAL
EPSS
74.1%
2024 CWE-918 0 PoCs

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.

CVE-2024-43415
decidim-module-decidim_awesome Database
9.0
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.

CVE-2024-29855
Recovery Orchestrator General
9.0
CRITICAL
EPSS
19.1%
2024 1 PoC

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator