1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-2405
Float menu Web Windows
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

CVE-2024-2432
GlobalProtect App Networking Windows
4.5
MEDIUM
EPSS
0.4%
2024 CWE-269 2 PoCs

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

CVE-2024-3060
ENL Newsletter Web Database Windows
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks

CVE-2024-7655
Community by PeepSo – Download from PeepSo.com Web Windows
4.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-12581
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Web Windows
4.4
MEDIUM
EPSS
0.4%
2024 CWE-79 2 PoCs

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-9878
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Windows
4.4
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-9769
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Web Windows
4.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-21305
Windows 10 Version 1809 Windows
4.4
MEDIUM
EPSS
0.4%
2024 CWE-732 1 PoC

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

CVE-2024-1977
Restaurant Solutions – Checklist Web Windows
4.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-7618
Community by PeepSo – Download from PeepSo.com Web Windows
4.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-6011
Cost Calculator Builder Web Windows
4.4
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-22103
Software Genérico Windows
4.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

CVE-2024-12436
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-7862
blogintroduction-wordpress-plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12750
Competition Form Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-34029
Mattermost Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.

CVE-2024-8245
GamiPress Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-10634
Nokaut Offers Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack

CVE-2024-8009
Sensei LMS Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

CVE-2024-3410
DN Footer Contacts Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)