3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-9789
LyLme_spage Web Database
5.1
MEDIUM
EPSS
0.2%
2024 CWE-89 2 PoCs

A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6276
School Management System Web Database
5.1
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. This issue affects some unknown processing of the file teacher.php of the component Teacher Page. The manipulation of the argument update leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269489 was assigned to this vulnerability.

CVE-2024-9278
SCRM Web
5.1
MEDIUM
EPSS
0.0%
2024 CWE-434 1 PoC

A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of the file WxkConfig.php of the component Administrator Backend. The manipulation of the argument domain_verification_file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-6267
Service Provider Management System Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-79 3 PoCs

A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected by this vulnerability is an unknown functionality of the file system_info/index.php of the component System Info Page. The manipulation of the argument System Name/System Short Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269479.

CVE-2024-8084
Online Computer and Laptop Store Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file /php-ocls/classes/SystemSettings.php?f=update_settings of the component Setting Handler. The manipulation of the argument System Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-5043
Emlog Pro Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264740. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11304
utnserver Pro Web
5.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS). This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2024-8118
Grafana DevOps Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-653 1 PoC

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

CVE-2024-4899
SEOPress Web Windows
5.0
MEDIUM
EPSS
0.2%
2024 1 PoC

The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2024-9102
phpLDAPadmin Web Windows
5.0
MEDIUM
EPSS
0.1%
2024 CWE-1236 1 PoC

phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this could lead to CSV Formula Injection. NOTE: This vulnerability will not be addressed, the maintainer's position is that it is not the intention of phpLDAPadmin to control what data Administrators can put in their LDAP database, nor filter it on export.

CVE-2024-23998
Software Genérico Web Database
5.0
MEDIUM
EPSS
12.2%
2024 2 PoCs

goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.

CVE-2024-4529
Business Card Web Windows
5.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks

CVE-2024-10708
System Dashboard Web Windows ⚡ nuclei
4.9
MEDIUM
EPSS
8.5%
2024 1 PoC

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

CVE-2024-57785
Software Genérico Web
4.9
MEDIUM
EPSS
16.2%
2024 1 PoC

Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uploads.php.

CVE-2024-21261
Oracle Application Express Web Database
4.9
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. While the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Ora

CVE-2024-3112
Quotes and Tips by BestWebSoft Web Windows
4.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2024-9874
Poll Maker – Versus Polls, Anonymous Polls, Image Polls Web Database Windows
4.9
MEDIUM
EPSS
1.1%
2024 CWE-89 1 PoC

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-43443
OTRS Web
4.9
MEDIUM
EPSS
0.1%
2024 CWE-790 1 PoC

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

CVE-2024-1310
WooCommerce Web Windows
4.9
MEDIUM
EPSS
0.6%
2024 1 PoC

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

CVE-2024-1286
pmpro-membership-maps Web Windows
4.9
MEDIUM
EPSS
0.4%
2024 1 PoC

The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.