Loading HuntDB...

Recent Vulnerabilities with Exploits

Exploitable

Recently discovered vulnerabilities with known exploit templates, ordered by discovery date.

CVE-2024-45440 6 months, 2 weeks ago

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.

MEDIUM (5.3) EPSS: 79.7% 1 exploit
Drupal 11.x-dev - Full Path D…
CVE-2024-45309 6 months, 2 weeks ago

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.

UNKNOWN (0.0) EPSS: 81.8% 1 exploit
OneDev.io < 11.0.9 - Arbitrar…
CVE-2024-45507 6 months, 2 weeks ago

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

UNKNOWN (8.8) EPSS: 87.5% 1 exploit
Apache OFBiz - Remote Code Ex…
CVE-2024-29889 6 months, 2 weeks ago

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.

HIGH (7.1) EPSS: 53.7% 1 exploit
GLPI 10.0.10-10.0.14 - SQL In…
CVE-2024-29272 6 months, 2 weeks ago

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

MEDIUM (6.5) EPSS: 89.3% 1 exploit
VvvebJs < 1.7.5 - Arbitrary F…
CVE-2024-29824 6 months, 2 weeks ago

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CRITICAL (9.6) EPSS: 94.3% 1 exploit
Ivanti EPM - Remote Code Exec…
CVE-2024-29973 6 months, 2 weeks ago

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CRITICAL (9.8) EPSS: 93.7% 1 exploit
Zyxel NAS326 Firmware < V5.21…
CVE-2024-29972 6 months, 2 weeks ago

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CRITICAL (9.8) EPSS: 91.5% 1 exploit
Zyxel NAS326 Firmware < V5.21…
CVE-2024-29868 6 months, 2 weeks ago

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

CRITICAL (9.1) EPSS: 52.9% 1 exploit
Apache StreamPipes <= 0.93.0 …
CVE-2024-29059 6 months, 2 weeks ago

No description available

HIGH (7.5) EPSS: 93.7% 1 exploit
.NET Framework - Leaking ObjR…
CVE-2024-29269 6 months, 2 weeks ago

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

UNKNOWN (8.8) EPSS: 92.6% 1 exploit
Telesquare TLR-2005KSH - Rem…
CVE-2024-0305 6 months, 2 weeks ago

A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.

MEDIUM (5.3) EPSS: 93.5% 1 exploit
Ncast busiFacade - Remote Com…
CVE-2024-0012 6 months, 2 weeks ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

UNKNOWN (0.0) EPSS: 94.4% 1 exploit
PAN-OS Management Web Interfa…
CVE-2024-0235 6 months, 2 weeks ago

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

UNKNOWN (0.0) EPSS: 83.1% 1 exploit
EventON (Free < 2.2.8, Premiu…
CVE-2024-0250 6 months, 2 weeks ago

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

MEDIUM (6.1) EPSS: 20.1% 1 exploit
Analytics Insights for Google…
CVE-2024-0939 6 months, 2 weeks ago

A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

MEDIUM (6.3) EPSS: 87.3% 1 exploit
Smart S210 Management Platfor…
CVE-2024-0352 6 months, 2 weeks ago

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250120.

HIGH (7.3) EPSS: 91.2% 1 exploit
Likeshop < 2.5.7.20210311 - A…
CVE-2024-0881 6 months, 2 weeks ago

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

MEDIUM (5.4) EPSS: 11.5% 1 exploit
Combo Blocks < 2.2.76 - Impro…
CVE-2024-0986 6 months, 2 weeks ago

A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

MEDIUM (4.7) EPSS: 83.1% 1 exploit
Issabel Authenticated - Remot…
CVE-2024-0713 6 months, 2 weeks ago

No description available

UNKNOWN (0.0) EPSS: 1.0% 1 exploit
Monitorr Services Configurati…