4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-1751
Tutor LMS – eLearning and online course solution Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
35.2%
2024 CWE-89 0 PoCs

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-5606
Quiz and Survey Master (QSM) Web Database Windows
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

CVE-2024-26198
Microsoft Exchange Server 2019 Cumulative Update 14 Windows
8.8
HIGH
EPSS
2.7%
2024 CWE-426 2 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2024-6023
ContentLock Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-5630
Insert or Embed Articulate Content into WordPress Web Windows
8.8
HIGH
EPSS
1.1%
2024 1 PoC

The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

CVE-2024-10728
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Web Windows
8.8
HIGH
EPSS
76.1%
2024 CWE-862 1 PoC

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVE-2024-2018
WP Activity Log Premium Web Database Windows
8.8
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. One demonstrated attack included the injection of a PHP Object.

CVE-2024-6022
ContentLock Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-2376
WPQA Builder Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-9941
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.

CVE-2024-10629
GPX Viewer Web Windows
8.8
HIGH
EPSS
57.6%
2024 CWE-862 2 PoCs

The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() function in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-13146
Booknetic Web Windows
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVE-2024-5767
sitetweet Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-0670
Checkmk Windows
8.8
HIGH
EPSS
0.2%
2024 CWE-427 2 PoCs

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

CVE-2024-3940
reCAPTCHA Jetpack Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-0856
Appointment Booking Calendar Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.

CVE-2024-6024
ContentLock Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack

CVE-2024-10674
Th Shop Mania Web Windows
8.8
HIGH
EPSS
41.2%
2024 CWE-862 1 PoC

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.

CVE-2019-1151
Windows 10 Version 1703 Windows
8.8
HIGH
EPSS
28.4%
2019 1 PoC

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit the vulnerability: In a web-based attack scenario

CVE-2019-1149
Windows 10 Version 1703 Windows
8.8
HIGH
EPSS
31.9%
2019 1 PoC

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit the vulnerability: In a web-based attack scenario