3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-6325
FactoryTalk® System Services (installed via FTPM) Web
6.0
MEDIUM
EPSS
0.0%
2024 CWE-269 2 PoCs

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html  by implementing CIP security and did not update to the versions of the software CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html  and CVE-2022-1161. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html

CVE-2024-27631
Software Genérico Web
6.0
MEDIUM
EPSS
0.4%
2024 3 PoCs

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

CVE-2024-23634
geoserver Web
6.0
MEDIUM
EPSS
1.1%
2024 CWE-20 1 PoC

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists in versions prior to 2.23.5 and 2.24.2 that enables an authenticated administrator with permissions to modify stores through the REST Coverage Store or Data Store API to rename arbitrary files and directories with a name that does not end in `.zip`. Store file uploads rename zip files to have a `.zip` extension if it doesn't already have one before unzipping the file. This is fine for file and url upload methods where the files will b

CVE-2024-37791
Software Genérico Web Database Cloud
6.0
MEDIUM
EPSS
2.7%
2024 1 PoC

DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.

CVE-2024-24554
Bludit Web
6.0
MEDIUM
EPSS
0.1%
2024 CWE-338 1 PoC

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.

CVE-2024-6961
Software Genérico Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-611 1 PoC

RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL documents from external sources are vulnerable to XXE, which may cause leakage of internal file data via the SYSTEM entity.

CVE-2024-46635
Software Genérico Web
5.9
MEDIUM
EPSS
1.0%
2024 1 PoC

An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.

CVE-2024-10105
Job Postings Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5033
SULly Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-1905
Smart Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6243
HTML Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

CVE-2024-4752
EventON Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3472
Modal Window Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-5626
Inline Related Posts Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-9230
PowerPress Podcasting plugin by Blubrry Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks

CVE-2024-3113
FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5604
Bug Library Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2118
Social Media Share Buttons & Social Sharing Icons Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-11644
WP-SVG Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP-SVG WordPress plugin through 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-8652
NetCat CMS Web
5.9
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.