CVE-2024-24520
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
CVSS
7.8
Alto
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 21 mar 2024 · Última mod.: 9 jul 2026 · CWE-94
0.4%EPSS · 30 días0.4%
2026-06-302026-07-19
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
- github.comhttps://github.com/capture0x/leptoncms
- github.comhttps://github.com/xF9979/LEPTON-CMS
- packetstormsecurity.comhttps://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html
- www.exploit-db.comhttps://www.exploit-db.com/exploits/51949
- github.comhttps://github.com/capture0x/leptoncms
- github.comhttps://github.com/xF9979/LEPTON-CMS
- packetstormsecurity.comhttps://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html
- www.exploit-db.comhttps://www.exploit-db.com/exploits/51949
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-32489.8 CRÍ100.0%
KEV—80Langflow Missing Authentication Vulnerability5dCVE-2026-341978.8 ALT99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability5dCVE-2026-154107.2 ALT71.1%
KEV—71SonicWall SMA1000 Appliances Code Injection Vulnerability4dCVE-2025-670389.8 CRÍ55.3%
KEV—67Lantronix EDS5000 Code Injection Vulnerability14dCVE-2021-416539.8 CRÍ99.5%
——30The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.11dCVE-2023-362558.8 ALT99.0%
——30An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.11d