4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-7389
Forminator Forms – Contact Form, Payment Form & Custom Form Builder Web Windows
7.5
HIGH
EPSS
2.8%
2024 CWE-522 3 PoCs

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.

CVE-2024-7713
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows
7.5
HIGH
EPSS
0.4%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it

CVE-2024-8484
REST API TO MiniProgram Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
88.8%
2024 CWE-89 1 PoC

The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-12404
CF Internal Link Shortcode Web Database Windows
7.5
HIGH
EPSS
24.7%
2024 CWE-89 1 PoC

The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-10628
Quiz Maker Business Web Database Windows
7.5
HIGH
EPSS
0.2%
2024 CWE-89 1 PoC

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: The three variations of

CVE-2024-36991
Splunk Enterprise Windows ⚡ nuclei
7.5
HIGH
EPSS
93.5%
2024 CWE-35 11 PoCs

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

CVE-2024-3756
MF Gig Calendar Web Windows
7.5
HIGH
EPSS
0.3%
2024 1 PoC

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

CVE-2024-38472
Apache HTTP Server Web Windows ⚡ nuclei
7.5
HIGH
EPSS
90.6%
2024 CWE-918 1 PoC

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.

CVE-2024-13483
LTL Freight Quotes – SAIA Edition Web Database Windows
7.5
HIGH
EPSS
3.9%
2024 CWE-89 1 PoC

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6973
SDP Client Windows
7.5
HIGH
EPSS
1.5%
2024 CWE-20 1 PoC

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

CVE-2024-4469
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.7%
2024 1 PoC

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

CVE-2024-13496
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
19.3%
2024 CWE-89 1 PoC

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This vulnerability was previously published as being fi

CVE-2024-38257
Windows 10 Version 1809 Web Windows
7.5
HIGH
EPSS
4.3%
2024 CWE-908 1 PoC

Microsoft AllJoyn API Information Disclosure Vulnerability

CVE-2024-5882
Ultimate Classified Listings Web Windows
7.5
HIGH
EPSS
2.3%
2024 1 PoC

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVE-2024-13481
LTL Freight Quotes – R+L Carriers Edition Web Database Windows
7.5
HIGH
EPSS
14.8%
2024 CWE-89 1 PoC

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-13479
LTL Freight Quotes – SEFL Edition Web Database Windows
7.5
HIGH
EPSS
5.2%
2024 CWE-89 1 PoC

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-7786
Sensei LMS Web Windows ⚡ nuclei
7.5
HIGH
EPSS
70.5%
2024 1 PoC

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

CVE-2024-11423
Gift Cards for WooCommerce Pro Web Windows
7.5
HIGH
EPSS
20.7%
2024 CWE-862 1 PoC

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances wi

CVE-2024-3657
Red Hat Directory Server 11.5 E4S for RHEL 8 Windows
7.5
HIGH
EPSS
0.5%
2024 CWE-20 1 PoC

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

CVE-2024-12849
Error Log Viewer By WP Guru Web Windows ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2024 CWE-22 2 PoCs

The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.