3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-40119
Software Genérico Web Networking
8.8
HIGH
EPSS
7.0%
2024 2 PoCs

Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a potential account takeover.

CVE-2024-5324
Waitlist Woocommerce ( Back in stock notifier ) Web Windows
8.8
HIGH
EPSS
43.7%
2024 CWE-862 1 PoC

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

CVE-2024-5630
Insert or Embed Articulate Content into WordPress Web Windows
8.8
HIGH
EPSS
1.1%
2024 1 PoC

The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

CVE-2024-55656
RedisBloom Web Database
8.8
HIGH
EPSS
13.1%
2024 CWE-190 1 PoC

RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. The integer overflow vulnerability allows an attacker (a redis client which knows the password) to allocate memory in the heap lesser than the required memory due to wraparound. Then read and write can be performed beyond this allocated memory, leading to info leak and OOB write. The integer overflow is in CMS.INITBYDIM command, which initialize a Count-Min Sketch to dimensions specified by user. It accepts two values (width and depth) and

CVE-2024-0858
Innovs HR Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.

CVE-2024-8252
Clean Login Web Windows ⚡ nuclei
8.8
HIGH
EPSS
44.2%
2024 CWE-98 0 PoCs

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-50858
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.

CVE-2024-55505
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2024 1 PoC

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

CVE-2024-40474
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

CVE-2024-22939
Software Genérico Web
8.8
HIGH
EPSS
1.7%
2024 1 PoC

Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

CVE-2024-4351
Tutor LMS Pro Web Windows
8.8
HIGH
EPSS
31.0%
2024 CWE-89 1 PoC

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.

CVE-2024-30188
Apache DolphinScheduler Web ⚡ nuclei
8.8
HIGH
EPSS
88.5%
2024 CWE-20 0 PoCs

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue.

CVE-2024-36597
Software Genérico Web Database
8.8
HIGH
EPSS
87.0%
2024 1 PoC

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

CVE-2024-4352
Tutor LMS Pro Web Database Windows
8.8
HIGH
EPSS
23.3%
2024 CWE-862 1 PoC

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the ‘year’ parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sens

CVE-2024-6075
wp-cart-for-digital-products Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-28888
Foxit Reader Web
8.8
HIGH
EPSS
4.1%
2024 CWE-416 3 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2024-6023
ContentLock Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-56116
Software Genérico Web
8.8
HIGH
EPSS
12.1%
2024 1 PoC

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

CVE-2024-55506
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

CVE-2024-11267
JSP Store Locator Web Database Windows
8.8
HIGH
EPSS
1.3%
2024 1 PoC

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.