3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-49418
GamingHub Web
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.

CVE-2024-44653
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

CVE-2024-50972
Software Genérico Web Database
6.5
MEDIUM
EPSS
4.8%
2024 1 PoC

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

CVE-2024-44630
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.

CVE-2024-44651
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

CVE-2024-43335
Responsive Blocks – WordPress Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.

CVE-2024-1756
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name

CVE-2024-25227
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.6%
2024 2 PoCs

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.

CVE-2024-50971
Software Genérico Web Database
6.5
MEDIUM
EPSS
4.8%
2024 1 PoC

A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.

CVE-2024-2509
Gutenberg Blocks by Kadence Blocks Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-44648
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.

CVE-2024-7135
Tainacan Web Windows
6.5
MEDIUM
EPSS
48.0%
2024 CWE-862 2 PoCs

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-46437
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials, by sending a specially crafted HTTP POST request to the getQuickCfgWifiAndLogin function, bypassing authentication checks.

CVE-2024-3749
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user

CVE-2024-23446
Kibana Web
6.5
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

CVE-2024-1295
events-calendar-pro Web Windows
6.5
MEDIUM
EPSS
0.9%
2024 1 PoC

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

CVE-2024-9224
Hello World Web Windows
6.5
MEDIUM
EPSS
50.8%
2024 CWE-22 1 PoC

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-6025
Quiz and Survey Master (QSM) Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

CVE-2024-2430
Website Content in Page or Post Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3591
Geo Controller Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.