13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-31413
Filebeat Web
5.5
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.

CVE-2023-6617
Simple Student Attendance System Web Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247254 is the identifier assigned to this vulnerability.

CVE-2023-7184
Fakabao Web Database
5.5
MEDIUM
EPSS
0.0%
2023 CWE-89 2 PoCs

A vulnerability was found in 7-card Fakabao up to 1.0_build20230805 and classified as critical. Affected by this issue is some unknown functionality of the file shop/notify.php. The manipulation of the argument out_trade_no leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249386 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6581
DAR-7000 Web Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects unknown code of the file /user/inc/workidajax.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0360
Hospital Management System Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250127.

CVE-2024-1251
OA 2017 Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-252990 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11404
django Filer Web
5.5
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.This issue affects django Filer: from 3 before 3.3.

CVE-2024-4627
Rank Math SEO Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-40137
Software Genérico Web
5.5
MEDIUM
EPSS
0.5%
2024 1 PoC

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

CVE-2024-1252
OA 2017 Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.

CVE-2024-37674
Software Genérico Web
5.5
MEDIUM
EPSS
3.6%
2024 1 PoC

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

CVE-2024-52559
Linux Web
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit() The "submit->cmd[i].size" and "submit->cmd[i].offset" variables are u32 values that come from the user via the submit_lookup_cmds() function. This addition could lead to an integer wrapping bug so use size_add() to prevent that. Patchwork: https://patchwork.freedesktop.org/patch/624696/

CVE-2024-1704
CRMEB Web
5.5
MEDIUM
EPSS
0.1%
2024 CWE-22 1 PoC

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5285
wp-affiliate-platform Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

CVE-2024-0466
Employee Profile Management System Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250571.

CVE-2024-4759
Mime Types Extended Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-3824
Base64 Encoder/Decoder Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2024-34959
Software Genérico Web
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.

CVE-2024-57360
Software Genérico Web
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

CVE-2024-0357
Eva Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of the component HTTP POST Request Handler. The manipulation of the argument property leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250124.