1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-3643
Newsletter Popup Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack

CVE-2024-3940
reCAPTCHA Jetpack Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-0670
Checkmk Windows
8.8
HIGH
EPSS
0.2%
2024 CWE-427 2 PoCs

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

CVE-2024-13146
Booknetic Web Windows
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVE-2024-3406
WP Prayer Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-57394
Software Genérico Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.

CVE-2024-3293
rtMedia for WordPress, BuddyPress and bbPress Web Database Windows
8.8
HIGH
EPSS
26.6%
2024 CWE-89 1 PoC

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6666
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Web Database Windows
8.8
HIGH
EPSS
0.8%
2024 CWE-89 2 PoCs

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Accounting Manager access (erp_ac_view_sales_summary capability) and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-10673
Top Store Web Windows
8.8
HIGH
EPSS
51.9%
2024 CWE-862 1 PoC

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.

CVE-2024-8252
Clean Login Web Windows ⚡ nuclei
8.8
HIGH
EPSS
44.2%
2024 CWE-98 0 PoCs

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-13933
FoodBakery | Delivery Restaurant Directory WordPress Theme Web Windows
8.8
HIGH
EPSS
0.2%
2024 CWE-352 1 PoC

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions. This makes it possible for unauthenticated attackers to delete arbitrary files, update theme options, export widget option

CVE-2024-20674
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
16.0%
2024 CWE-305 1 PoC

Windows Kerberos Security Feature Bypass Vulnerability

CVE-2024-49039
🔥 KEV Windows Server 2025 Windows
8.8
HIGH
EPSS
63.7%
2024 CWE-287 2 PoCs

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-5034
SULly Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-12594
Login Page Styler – Custom WordPress Login Page Customizer & Security Web Windows
8.8
HIGH
EPSS
3.0%
2024 CWE-862 1 PoC

The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'lps_generate_temp_access_url' AJAX action in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to login as other users such as subscribers.

CVE-2024-6244
PZ Frontend Manager Web Windows
8.8
HIGH
EPSS
12.6%
2024 2 PoCs

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-6024
ContentLock Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack

CVE-2024-13418
Benaa Framework Web Windows
8.8
HIGH
EPSS
1.4%
2024 CWE-434 1 PoC

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote code execution possible. This issue was escalated to Envato over two months from the date of this disclosure and the issue, while partially patched, is still vulnerable.

CVE-2024-3217
WP Directory Kit Web Database Windows
8.8
HIGH
EPSS
52.9%
2024 CWE-89 1 PoC

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11638
Gtbabel Web Windows
8.8
HIGH
EPSS
0.5%
2024 1 PoC

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.