1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-0365
Fancy Product Designer Web Database Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

CVE-2024-7714
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
23.9%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVE-2024-7859
Visual Sound Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-10631
Countdown Timer for WordPress Block Editor Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13896
WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue

CVE-2024-5072
Server Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.

CVE-2024-7817
Misiek Photo Album Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack

CVE-2024-5522
HTML5 Video Player Web Database Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.8%
2024 6 PoCs

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2024-36049
Software Genérico Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable information (PII) and especially payroll data and the ability to impersonate legitimate users with respect to the audit log.

CVE-2024-7135
Tainacan Web Windows
6.5
MEDIUM
EPSS
48.0%
2024 CWE-862 2 PoCs

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-43335
Responsive Blocks – WordPress Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.

CVE-2024-6853
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-3749
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user

CVE-2024-2509
Gutenberg Blocks by Kadence Blocks Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-1295
events-calendar-pro Web Windows
6.5
MEDIUM
EPSS
0.9%
2024 1 PoC

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

CVE-2024-3591
Geo Controller Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2024-2843
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks

CVE-2024-9224
Hello World Web Windows
6.5
MEDIUM
EPSS
50.8%
2024 CWE-22 1 PoC

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-6025
Quiz and Survey Master (QSM) Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

CVE-2024-1309
Niagara Framework Windows
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 3 PoCs

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.