1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-5102
Antivirus Windows
7.3
HIGH
EPSS
0.1%
2024 CWE-1284 1 PoC

A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the s

CVE-2024-23769
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

CVE-2024-35061
Software Genérico Windows
7.3
HIGH
EPSS
1.4%
2024 1 PoC

NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.

CVE-2024-10958
WP Photo Album Plus Web Windows
7.3
HIGH
EPSS
55.7%
2024 CWE-94 1 PoC

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-13346
Avada | Website Builder For WordPress & WooCommerce Web Windows
7.3
HIGH
EPSS
41.3%
2024 CWE-94 1 PoC

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-0683
Bulgarisation for WooCommerce Web Windows
7.3
HIGH
EPSS
26.4%
2024 CWE-862 1 PoC

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and delete labels.

CVE-2024-7980
Chrome Windows
7.3
HIGH
EPSS
0.0%
2024 1 PoC

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)

CVE-2024-6750
Social Auto Poster Web Windows
7.3
HIGH
EPSS
0.3%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.

CVE-2024-9162
All-in-One WP Migration and Backup Web Windows
7.2
HIGH
EPSS
62.6%
2024 CWE-94 1 PoC

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.

CVE-2024-7129
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
7.2
HIGH
EPSS
12.7%
2024 1 PoC

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins

CVE-2024-12773
Altra Side Menu Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-10793
WP Activity Log Web Windows
7.2
HIGH
EPSS
68.7%
2024 CWE-79 3 PoCs

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.

CVE-2024-7766
Adicon Server Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-8379
Cost Calculator Builder Web Database Windows
7.2
HIGH
EPSS
0.6%
2024 1 PoC

The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2024-10247
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Web Database Windows
7.2
HIGH
EPSS
1.3%
2024 CWE-89 1 PoC

The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-13618
aoa-downloadable Web Windows
7.2
HIGH
EPSS
0.2%
2024 1 PoC

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

CVE-2024-6354
Remote Desktop Manager Windows
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

CVE-2024-1068
404 Solution Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.

CVE-2024-10499
AI Engine Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-9831
Taskbuilder Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks