94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-12252
SEO LAT Auto Post Web Windows
9.8
CRITICAL
EPSS
66.5%
2024 CWE-94 2 PoCs

The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.

CVE-2024-54756
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2024 2 PoCs

A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.

CVE-2024-10441
DiskStation Manager (DSM) Web
9.8
CRITICAL
EPSS
1.9%
2024 CWE-116 1 PoC

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2024-4323
Fluent Bit Web
9.8
CRITICAL
EPSS
84.6%
2024 CWE-122 4 PoCs

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

CVE-2024-54239
Eyewear prescription form General
9.8
CRITICAL
EPSS
2.9%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.

CVE-2024-50623
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2024 CWE-434 5 PoCs

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

CVE-2024-31849
Connect General ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 CWE-22 1 PoC

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

CVE-2024-44849
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2024 1 PoC

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

CVE-2024-4577
🔥 KEV PHP Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-78 85 PoCs

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVE-2024-48061
Software Genérico General
9.8
CRITICAL
EPSS
13.2%
2024 2 PoCs

langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.

CVE-2024-6159
Push Notification for Post and BuddyPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
9.8%
2024 1 PoC

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-45275
mbNET.mini General
9.8
CRITICAL
EPSS
3.4%
2024 CWE-798 1 PoC

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

CVE-2024-36445
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

CVE-2024-24401
Software Genérico Web Database
9.8
CRITICAL
EPSS
58.0%
2024 1 PoC

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

CVE-2024-36389
DeviceHub General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-330 1 PoC

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

CVE-2024-33898
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.

CVE-2024-34833
Software Genérico Web
9.8
CRITICAL
EPSS
42.1%
2024 2 PoCs

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

CVE-2024-46451
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

CVE-2024-31705
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2024 2 PoCs

An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.