4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-7817
Misiek Photo Album Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack

CVE-2024-36049
Software Genérico Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable information (PII) and especially payroll data and the ability to impersonate legitimate users with respect to the audit log.

CVE-2024-2509
Gutenberg Blocks by Kadence Blocks Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-1295
events-calendar-pro Web Windows
6.5
MEDIUM
EPSS
0.9%
2024 1 PoC

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

CVE-2024-6025
Quiz and Survey Master (QSM) Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

CVE-2024-0679
ColorMag Web Windows
6.5
MEDIUM
EPSS
9.8%
2024 CWE-862 1 PoC

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.

CVE-2024-8031
Secure Downloads Web Windows
6.5
MEDIUM
EPSS
1.9%
2024 1 PoC

The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.

CVE-2024-9224
Hello World Web Windows
6.5
MEDIUM
EPSS
50.8%
2024 CWE-22 1 PoC

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-1982
WPvivid — Backup, Migration & Staging Web Database Windows
6.5
MEDIUM
EPSS
0.4%
2024 CWE-862 1 PoC

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vulnerability or trigger a DoS.

CVE-2024-12774
Altra Side Menu Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack

CVE-2024-2697
socialdriver-framework Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2024-7864
Favicon Generator (CLOSED) Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server

CVE-2024-3963
Giveaways and Contests by RafflePress Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-7859
Visual Sound Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-43335
Responsive Blocks – WordPress Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.

CVE-2024-3591
Geo Controller Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2024-2843
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks

CVE-2024-6496
Light Poll Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform such action via a CSRF attack

CVE-2024-52926
Privilege Manager Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-269 1 PoC

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

CVE-2024-30043
Microsoft SharePoint Enterprise Server 2016 Windows
6.5
MEDIUM
EPSS
54.1%
2024 CWE-611 1 PoC

Microsoft SharePoint Server Information Disclosure Vulnerability