4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6977
SDP Client Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-532 1 PoC

A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.

CVE-2024-6230
پلاگین پرداخت دلخواه Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-8094
Ntz Antispam Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-38030
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
67.5%
2024 CWE-200 2 PoCs

Windows Themes Spoofing Vulnerability

CVE-2024-7514
Comments Import & Export Web Windows
6.5
MEDIUM
EPSS
47.4%
2024 CWE-22 1 PoC

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The issue was partially fixed in version 2.3.8 and fully fixed in 2.3.9

CVE-2024-4260
Page Builder Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

CVE-2024-12301
JSP Store Locator Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-1756
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name

CVE-2024-6852
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1309
Niagara Framework Windows
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 3 PoCs

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.

CVE-2024-6853
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-13896
WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue

CVE-2024-10631
Countdown Timer for WordPress Block Editor Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6490
Master Slider Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

CVE-2024-0365
Fancy Product Designer Web Database Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

CVE-2024-12163
goodlayers-core Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

CVE-2024-4533
KKProgressbar2 Free Web Database Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks

CVE-2024-7714
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
23.9%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVE-2024-1747
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.

CVE-2024-6412
HTML Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks