3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-0811
Chrome Web
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

CVE-2024-8082
Widgets Reset Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-2823
DedeCMS Web
4.3
MEDIUM
EPSS
0.0%
2024 CWE-352 1 PoC

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/mda_main.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257710 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3477
Popup Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks

CVE-2024-0726
Student Project Allocation System Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-79 2 PoCs

A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin_login.php of the component Admin Login Module. The manipulation of the argument msg with the input test%22%3Cscript%3Ealert(%27Torada%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251549 was assigned to this vulnerability.

CVE-2024-0286
Hospital Management System Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of the component Contact Form. The manipulation of the argument Name/Email/Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249843.

CVE-2024-40443
Software Genérico Web Database
4.3
MEDIUM
EPSS
6.3%
2024 1 PoC

SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php

CVE-2024-4474
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
2.8%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-4969
Widget Bundle Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

CVE-2024-5169
Video Widget Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-21206
Oracle Enterprise Command Center Framework Web Database
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2024-26349
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_translation.php

CVE-2024-13306
Maps Plugin using Google Maps for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4875
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Web Windows
4.3
MEDIUM
EPSS
3.8%
2024 CWE-862 1 PoC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update options such as users_can_register, which can lead to unauthorized user registration.

CVE-2024-2277
G-Prescription Gynaecology & OBS Consultation Software Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Setting/change_password_save of the component Password Reset Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256046 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4172
idcCMS Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability classified as problematic was found in idcCMS 1.35. Affected by this vulnerability is an unknown functionality of the file /admin/admin_cl.php?mudi=revPwd. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261991.

CVE-2024-1745
Testimonial Slider Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them.

CVE-2024-0902
Fancy Product Designer Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4957
Frontend Checklist Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3151
Multi-Store Inventory Management System Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability, which was classified as problematic, was found in Bdtask Multi-Store Inventory Management System up to 20240325. Affected is an unknown function of the file /stockmovment/stockmovment/delete/ of the component Stock Movement Page. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258924. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.