3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-4934
Quiz and Survey Master (QSM) Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-40137
Software Genérico Web
5.5
MEDIUM
EPSS
0.5%
2024 1 PoC

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

CVE-2024-11404
django Filer Web
5.5
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.This issue affects django Filer: from 3 before 3.3.

CVE-2024-1252
OA 2017 Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.

CVE-2024-52559
Linux Web
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit() The "submit->cmd[i].size" and "submit->cmd[i].offset" variables are u32 values that come from the user via the submit_lookup_cmds() function. This addition could lead to an integer wrapping bug so use size_add() to prevent that. Patchwork: https://patchwork.freedesktop.org/patch/624696/

CVE-2024-57360
Software Genérico Web
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

CVE-2024-57784
Software Genérico Web
5.5
MEDIUM
EPSS
14.3%
2024 1 PoC

An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.

CVE-2024-4759
Mime Types Extended Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-1704
CRMEB Web
5.5
MEDIUM
EPSS
0.1%
2024 CWE-22 1 PoC

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1251
OA 2017 Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-252990 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0344
TimeMail Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of the file check.php. The manipulation of the argument c leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250112.

CVE-2024-31211
wordpress-develop Web Windows
5.5
MEDIUM
EPSS
39.7%
2024 CWE-502 1 PoC

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

CVE-2024-3048
Bannerlid Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

CVE-2024-37674
Software Genérico Web
5.5
MEDIUM
EPSS
3.6%
2024 1 PoC

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

CVE-2024-5285
wp-affiliate-platform Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

CVE-2024-34959
Software Genérico Web
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.

CVE-2024-0357
Eva Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of the component HTTP POST Request Handler. The manipulation of the argument property leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250124.

CVE-2024-44919
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.

CVE-2024-46879
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.

CVE-2024-10504
Contact Form, Survey, Quiz & Popup Form Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.