3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-21583
github.com/gitpod-io/gitpod/components/server/go/pkg/lib Web
4.1
MEDIUM
EPSS
0.3%
2024 CWE-15 6 PoCs

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/public-api-server before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/server before main-gha.27122; versions of the package @gitpod/gitpo

CVE-2024-9828
Taskbuilder Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks

CVE-2024-12109
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-10009
Melapress File Monitor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-10638
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-42906
Software Genérico Web
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.

CVE-2024-9689
Post From Frontend Web Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack

CVE-2024-33883
Software Genérico Web
4.0
MEDIUM
EPSS
1.3%
2024 1 PoC

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

CVE-2024-4755
Google CSE Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-34650
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

CVE-2024-5473
Simple Photoswipe Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4841
parisneo/lollms-webui Web ⚡ nuclei
4.0
MEDIUM
EPSS
8.5%
2024 CWE-29 0 PoCs

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.

CVE-2024-34647
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

CVE-2024-21100
Commerce Platform Web Database
4.0
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. While the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Sco

CVE-2024-1784
Limbas Web Database
3.9
LOW
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5030
CM Table Of Contents Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-3628
EasyEvent Web Windows
3.8
LOW
EPSS
0.2%
2024 1 PoC

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2972
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4145
Search & Replace Web Database Windows
3.8
LOW
EPSS
0.5%
2024 1 PoC

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).

CVE-2024-3076
MM-email2image Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack