1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6366
User Profile Builder Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
91.5%
2024 3 PoCs

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

CVE-2024-3673
Web Directory Free Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
92.2%
2024 2 PoCs

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

CVE-2024-5450
Bug Library Web Windows
9.1
CRITICAL
EPSS
2.1%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

CVE-2024-5973
MasterStudy LMS WordPress Plugin Web Windows
9.1
CRITICAL
EPSS
0.9%
2024 1 PoC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVE-2024-5975
CZ Loan Management Web Database Windows ⚡ nuclei
9.1
CRITICAL
EPSS
43.9%
2024 1 PoC

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-7385
WP Simple HTML Sitemap Web Database Windows
9.1
CRITICAL
EPSS
13.1%
2024 CWE-89 1 PoC

The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-40898
Apache HTTP Server Web Windows
9.1
CRITICAL
EPSS
0.7%
2024 CWE-918 4 PoCs

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

CVE-2024-4180
The Events Calendar Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
42.4%
2024 1 PoC

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

CVE-2024-38124
Windows Server 2019 Windows
9.0
CRITICAL
EPSS
0.3%
2024 CWE-287 1 PoC

Windows Netlogon Elevation of Privilege Vulnerability

CVE-2024-3474
Wow Skype Buttons Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2024-8252
Clean Login Web Windows ⚡ nuclei
8.8
HIGH
EPSS
44.2%
2024 CWE-98 0 PoCs

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-4351
Tutor LMS Pro Web Windows
8.8
HIGH
EPSS
31.0%
2024 CWE-89 1 PoC

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.

CVE-2024-9965
Chrome Windows
8.8
HIGH
EPSS
1.7%
2024 1 PoC

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-57394
Software Genérico Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.

CVE-2024-6244
PZ Frontend Manager Web Windows
8.8
HIGH
EPSS
12.6%
2024 2 PoCs

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-5324
Waitlist Woocommerce ( Back in stock notifier ) Web Windows
8.8
HIGH
EPSS
43.7%
2024 CWE-862 1 PoC

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

CVE-2024-6975
SDP Client Windows
8.8
HIGH
EPSS
0.1%
2024 CWE-426 1 PoC

Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

CVE-2024-29988
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
60.5%
2024 CWE-693 2 PoCs

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-6666
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Web Database Windows
8.8
HIGH
EPSS
0.8%
2024 CWE-89 2 PoCs

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Accounting Manager access (erp_ac_view_sales_summary capability) and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.