3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-3749
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user

CVE-2024-46437
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials, by sending a specially crafted HTTP POST request to the getQuickCfgWifiAndLogin function, bypassing authentication checks.

CVE-2024-7714
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
23.9%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVE-2024-1114
openBI Web
6.5
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /application/index/controller/Screen.php. The manipulation of the argument fileUrl leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252472.

CVE-2024-44653
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

CVE-2024-12105
WhatsUp Gold Web
6.5
MEDIUM
EPSS
7.9%
2024 CWE-22 1 PoC

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

CVE-2024-4533
KKProgressbar2 Free Web Database Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks

CVE-2024-49418
GamingHub Web
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.

CVE-2024-6855
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-0365
Fancy Product Designer Web Database Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

CVE-2024-22411
avo Web
6.5
MEDIUM
EPSS
5.8%
2024 CWE-79 1 PoC

Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.3.0 and 2.47.0 releases of Avo. Users are advised to upgrade.

CVE-2024-12163
goodlayers-core Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

CVE-2024-44639
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.

CVE-2024-3748
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user

CVE-2024-45589
Software Genérico Web Cloud
6.5
MEDIUM
EPSS
7.8%
2024 2 PoCs

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

CVE-2024-6490
Master Slider Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

CVE-2024-30986
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter.

CVE-2024-50972
Software Genérico Web Database
6.5
MEDIUM
EPSS
4.8%
2024 1 PoC

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

CVE-2024-10631
Countdown Timer for WordPress Block Editor Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-50970
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.