1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13878
SpotBot Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-9191
Okta Verify for Windows Windows
7.1
HIGH
EPSS
0.2%
2024 CWE-276 1 PoC

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered via routine penetration testing. Note: A precondition of this vulnerability is that the user must be using the Okta Device Access passwordless feature. Okta Device Access users not using passwordless are not affected, and customers only using Okta Verify on platforms other than Windows, or only using FastPass are not aff

CVE-2024-13631
Om Stripe Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13352
Legull Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.8%
2024 1 PoC

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0150
NVIDIA GPU Display Driver, vGPU software Windows
7.1
HIGH
EPSS
0.1%
2024 CWE-787 1 PoC

NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before the beginning of a buffer. A successful exploit of this vulnerability might lead to information disclosure, denial of service, or data tampering.

CVE-2024-13875
WP-PManager Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13884
Limit Bio Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13836
WP Login Control Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-3111
Interactive Content Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues

CVE-2024-21543
djoser Windows
7.1
HIGH
EPSS
0.2%
2024 CWE-287 1 PoC

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

CVE-2024-13330
JustRows free Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12878
Custom Block Builder Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.7%
2024 1 PoC

The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13625
Tube Video Ads Lite Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.7%
2024 1 PoC

The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-37259
The Ultimate WordPress Toolkit – WP Extended Web Windows ⚡ nuclei
7.1
HIGH
EPSS
11.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through <= 2.4.7.

CVE-2024-12708
Bulk Me Now! Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5287
wp-affiliate-platform Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

CVE-2024-12749
Competition Form Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-4531
Business Card Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

CVE-2024-6529
Ultimate Classified Listings Web Windows
7.1
HIGH
EPSS
52.4%
2024 2 PoCs

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13863
Stylish Google Sheet Reader 4.0 Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin