7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-58282
Serendipity Web
8.6
HIGH
EPSS
0.3%
2024 CWE-434 1 PoC

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server.

CVE-2024-13617
aoa-downloadable Web Windows
8.6
HIGH
EPSS
0.3%
2024 1 PoC

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

CVE-2024-21674
Confluence Data Center General
8.6
HIGH
EPSS
2.5%
2024 2 PoCs

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, no impact to integrity, no impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if

CVE-2024-6788
CHARX SEC-3000 General
8.6
HIGH
EPSS
5.5%
2024 CWE-1392 1 PoC

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.

CVE-2024-39713
Rocket.Chat General ⚡ nuclei
8.6
HIGH
EPSS
89.5%
2024 1 PoC

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

CVE-2024-34235
Software Genérico General
8.6
HIGH
EPSS
0.4%
2024 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.

CVE-2024-36117
reposilite General ⚡ nuclei
8.6
HIGH
EPSS
74.1%
2024 CWE-22 0 PoCs

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.

CVE-2024-6420
Hide My WP Ghost Web Windows ⚡ nuclei
8.6
HIGH
EPSS
36.9%
2024 1 PoC

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

CVE-2024-12971
Pandora FMS General
8.6
HIGH
EPSS
83.1%
2024 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

CVE-2024-58279
appRain CMF Web
8.6
HIGH
EPSS
0.4%
2024 CWE-434 1 PoC

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.

CVE-2024-58305
WonderCMS Web
8.6
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVE-2024-9491
Configuration Wizard 2 General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-1061
Software Genérico Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
83.4%
2024 CWE-89 1 PoC

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

CVE-2024-13726
Themes Coder Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
15.2%
2024 1 PoC

The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-31851
Sync General ⚡ nuclei
8.6
HIGH
EPSS
89.3%
2024 CWE-22 1 PoC

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

CVE-2024-24429
Software Genérico General
8.6
HIGH
EPSS
0.2%
2024 1 PoC

A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

CVE-2024-9987
Pandora FMS Database
8.6
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.

CVE-2024-9496
USBXpress Dev Kit General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-9492
Flash Programming Utility General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.