7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28741
Software Genérico Web
8.8
HIGH
EPSS
88.0%
2024 3 PoCs

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

CVE-2024-5717
Unified SecOps Platform Web
8.8
HIGH
EPSS
1.0%
2024 CWE-78 1 PoC

Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the implementation of the HTTP API. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the con

CVE-2024-48441
Software Genérico Networking
8.8
HIGH
EPSS
0.3%
2024 2 PoCs

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

CVE-2024-38189
🔥 KEV Microsoft Office 2019 General
8.8
HIGH
EPSS
43.7%
2024 CWE-20 1 PoC

Microsoft Project Remote Code Execution Vulnerability

CVE-2024-1672
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-11075
SICK Incoming Goods Suite DevOps Networking
8.8
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVE-2024-34221
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

CVE-2024-11393
Transformers General
8.8
HIGH
EPSS
79.5%
2024 CWE-502 1 PoC

Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnera

CVE-2024-2763
AC10U General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257600. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-25092
NextMove Lite General
8.8
HIGH
EPSS
71.4%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

CVE-2024-27497
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
81.9%
2024 0 PoCs

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

CVE-2024-22779
Software Genérico General
8.8
HIGH
EPSS
13.3%
2024 1 PoC

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

CVE-2024-40474
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

CVE-2024-5792
Houzez CRM Web Database Windows
8.8
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-48217
Software Genérico General
8.8
HIGH
EPSS
1.4%
2024 1 PoC

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

CVE-2024-28139
Scan2Net General
8.8
HIGH
EPSS
0.3%
2024 CWE-250 2 PoCs

The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.

CVE-2024-49039
🔥 KEV Windows Server 2025 Windows
8.8
HIGH
EPSS
63.7%
2024 CWE-287 2 PoCs

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-42756
Software Genérico General
8.8
HIGH
EPSS
20.2%
2024 1 PoC

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

CVE-2024-3807
Porto Web Windows
8.8
HIGH
EPSS
5.5%
2024 CWE-98 1 PoC

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0

CVE-2024-12594
Login Page Styler – Custom WordPress Login Page Customizer & Security Web Windows
8.8
HIGH
EPSS
3.0%
2024 CWE-862 1 PoC

The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'lps_generate_temp_access_url' AJAX action in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to login as other users such as subscribers.