7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9987
Pandora FMS Database
8.6
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.

CVE-2024-58284
PopojiCMS Web
8.6
HIGH
EPSS
0.6%
2024 CWE-94 1 PoC

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.

CVE-2024-54448
LogicalDOC Community General
8.6
HIGH
EPSS
0.1%
2024 CWE-94 1 PoC

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attack. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVE-2024-13726
Themes Coder Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
15.2%
2024 1 PoC

The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-32830
BuddyForms General
8.6
HIGH
EPSS
1.3%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.

CVE-2024-47076
libcupsfilters General
8.6
HIGH
EPSS
73.9%
2024 CWE-20 1 PoC

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

CVE-2024-48208
Software Genérico General
8.6
HIGH
EPSS
38.6%
2024 1 PoC

pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

CVE-2024-21542
luigi General
8.6
HIGH
EPSS
14.2%
2024 CWE-29 2 PoCs

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.

CVE-2024-21549
spatie/browsershot Web
8.6
HIGH
EPSS
0.0%
2024 CWE-20 2 PoCs

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).

CVE-2024-9492
Flash Programming Utility General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-5716
Unified SecOps Platform General
8.6
HIGH
EPSS
0.5%
2024 CWE-307 1 PoC

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password reset mechanism. The issue results from the lack of restriction of excessive authentication attempts. An attacker can leverage this vulnerability to reset a user's password and bypass authentication on the system. Was ZDI-CAN-24164.

CVE-2024-35340
Software Genérico General
8.6
HIGH
EPSS
2.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

CVE-2024-36416
SuiteCRM Web
8.6
HIGH
EPSS
44.7%
2024 CWE-779 1 PoC

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

CVE-2024-58313
xbtitFM Web
8.6
HIGH
EPSS
0.1%
2024 CWE-434 1 PoC

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

CVE-2024-34657
Samsung Notes General
8.6
HIGH
EPSS
3.0%
2024 1 PoC

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

CVE-2024-0368
Hustle – Email Marketing, Lead Generation, Optins, Popups Web Windows
8.6
HIGH
EPSS
1.6%
2024 CWE-522 2 PoCs

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.

CVE-2024-27453
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2024 1 PoC

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

CVE-2024-58305
WonderCMS Web
8.6
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVE-2024-58282
Serendipity Web
8.6
HIGH
EPSS
0.3%
2024 CWE-434 1 PoC

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server.

CVE-2024-48766
NetAlertX Web ⚡ nuclei
8.6
HIGH
EPSS
77.7%
2024 CWE-698 1 PoC

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.