1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-22830
Software Genérico Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate privileges from regular user to System or PPL level.

CVE-2024-13688
Admin and Site Enhancements (ASE) Web Windows
5.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request

CVE-2024-0710
GP Unique ID Web Windows
5.3
MEDIUM
EPSS
3.8%
2024 CWE-20 1 PoC

The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficient input validation. This makes it possible for unauthenticated attackers to tamper with the generation of a unique ID on a form submission and replace the generated unique ID with a user-controlled one, leading to a loss of integrity in cases where the ID's uniqueness is relied upon in a security-specific context.

CVE-2024-37152
argo-cd DevOps Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
80.2%
2024 CWE-287 0 PoCs

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

CVE-2024-6846
Chatbot with ChatGPT WordPress Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
6.3%
2024 1 PoC

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs

CVE-2024-3407
WP Prayer Web Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-1210
LearnDash LMS Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
23.8%
2024 CWE-200 1 PoC

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

CVE-2024-24692
Zoom Rooms Client for Windows Windows
5.3
MEDIUM
EPSS
0.1%
2024 CWE-367 1 PoC

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

CVE-2024-11396
Event Monster – Manager & Ticket Booking Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
54.2%
2024 CWE-359 1 PoC

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

CVE-2024-1526
Hubbub Lite Web Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

CVE-2024-4444
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Windows
5.3
MEDIUM
EPSS
0.9%
2024 CWE-420 2 PoCs

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

CVE-2024-11868
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
19.2%
2024 CWE-284 1 PoC

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course material.

CVE-2024-1208
LearnDash LMS Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
85.6%
2024 CWE-200 2 PoCs

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

CVE-2024-0624
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Web Windows
5.3
MEDIUM
EPSS
4.0%
2024 CWE-352 1 PoC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-2473
WPS Hide Login Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
14.3%
2024 CWE-863 0 PoCs

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.

CVE-2024-0593
Simple Job Board Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
6.7%
2024 CWE-862 0 PoCs

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

CVE-2024-5333
The Events Calendar Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
11.0%
2024 1 PoC

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

CVE-2024-6704
Comments – wpDiscuz Web Windows
5.3
MEDIUM
EPSS
8.4%
2024 CWE-79 1 PoC

The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled.

CVE-2024-34162
Multiple MFPs (multifunction printers) Windows
5.3
MEDIUM
EPSS
0.3%
2024 CWE-767 3 PoCs

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-0725
ProSSHD Networking Windows
5.3
MEDIUM
EPSS
2.0%
2024 CWE-404 1 PoC

A vulnerability was found in ProSSHD 1.2 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251548.