94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22836
Software Genérico General
9.8
CRITICAL
EPSS
38.2%
2024 1 PoC

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

CVE-2024-2055
Artica Proxy General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-288 2 PoCs

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

CVE-2024-57034
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

CVE-2024-55557
Software Genérico General
9.8
CRITICAL
EPSS
21.3%
2024 2 PoCs

ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

CVE-2024-10571
Chartify – WordPress Chart Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
87.3%
2024 CWE-98 2 PoCs

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-1554
Firefox Web
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.

CVE-2024-6671
WhatsUp Gold Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2024 CWE-89 0 PoCs

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CVE-2024-48514
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.

CVE-2024-8181
Flowise Web ⚡ nuclei
9.8
CRITICAL
EPSS
60.8%
2024 0 PoCs

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

CVE-2024-33789
Software Genérico Web
9.8
CRITICAL
EPSS
9.5%
2024 1 PoC

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

CVE-2024-37084
Spring Cloud Data Flow Web Cloud
9.8
CRITICAL
EPSS
83.3%
2024 5 PoCs

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

CVE-2024-36042
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

CVE-2024-54805
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.

CVE-2024-54803
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.

CVE-2024-8275
The Events Calendar Web Database Windows
9.8
CRITICAL
EPSS
83.5%
2024 CWE-89 3 PoCs

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.

CVE-2024-10924
Really Simple Security Pro multisite Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-288 16 PoCs

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

CVE-2024-24095
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

CVE-2024-41276
Software Genérico General
9.8
CRITICAL
EPSS
13.6%
2024 1 PoC

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.

CVE-2024-47575
🔥 KEV FortiManager Networking Cloud
9.8
CRITICAL
EPSS
93.9%
2024 CWE-306 14 PoCs

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

CVE-2024-28613
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.