4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-6444
Seriously Simple Podcasting Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
61.4%
2023 2 PoCs

The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.

CVE-2023-4631
DoLogin Security Web Windows
5.3
MEDIUM
EPSS
1.7%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

CVE-2023-51062
Software Genérico Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.

CVE-2023-7252
Tickera Web Windows
5.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.

CVE-2023-45503
Software Genérico Web Database Windows
5.3
MEDIUM
EPSS
1.8%
2023 1 PoC

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.

CVE-2023-6447
EventPrime Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

CVE-2023-22622
Software Genérico Web Windows
5.3
MEDIUM
EPSS
8.4%
2023 3 PoCs

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVE-2023-5561
WordPress Web Database Windows ⚡ nuclei
5.3
MEDIUM
EPSS
53.0%
2023 5 PoCs

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVE-2023-6155
Quiz Maker Web Windows
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

CVE-2023-2751
Upload Resume Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.

CVE-2023-7232
Backup and Restore WordPress Web Windows
5.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data

CVE-2023-5089
Defender Security Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
83.1%
2023 2 PoCs

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

CVE-2023-6334
Workforce Access Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: before 8.7.

CVE-2023-46666
Elastic Sharepoint Online Python Connector Database Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

CVE-2023-0443
AnyWhere Elementor Web Windows
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.

CVE-2024-4444
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Windows
5.3
MEDIUM
EPSS
0.9%
2024 CWE-420 2 PoCs

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

CVE-2024-0725
ProSSHD Networking Windows
5.3
MEDIUM
EPSS
2.0%
2024 CWE-404 1 PoC

A vulnerability was found in ProSSHD 1.2 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251548.

CVE-2024-6555
WP Popups – WordPress Popup builder Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
3.9%
2024 CWE-200 0 PoCs

The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

CVE-2024-13685
Admin and Site Enhancements (ASE) Web Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.

CVE-2024-0970
User Activity Tracking and Log Web Windows
5.3
MEDIUM
EPSS
0.5%
2024 1 PoC

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.