1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-11140
Real WP Shop Lite Ajax eCommerce Shopping Cart Web Windows
3.5
LOW
EPSS
0.6%
2024 1 PoC

The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10515
SEO Plugin by Squirrly SEO Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

CVE-2024-13585
Ajax Search Lite Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6711
Event Tickets with Ticket Scanner Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks

CVE-2024-10554
WordPress WP-Advanced-Search Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10558
Form Maker by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3996
Smart Post Show Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9771
WP-Recall Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4002
Carousel, Slider, Gallery by WP Carousel Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3471
Button Generator Web Windows
3.4
LOW
EPSS
0.1%
2024 1 PoC

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

CVE-2024-5198
ovpn-dco Networking Windows
3.3
LOW
EPSS
0.1%
2024 CWE-476 1 PoC

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

CVE-2024-22371
Apache Camel Web Windows
2.9
LOW
EPSS
0.9%
2024 1 PoC

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

CVE-2024-0080
nvTIFF Library Windows
2.8
LOW
EPSS
0.0%
2024 CWE-20 1 PoC

NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

CVE-2024-53921
Software Genérico Windows
2.8
LOW
EPSS
0.1%
2024 1 PoC

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

CVE-2024-6694
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Web Windows
2.7
LOW
EPSS
3.3%
2024 CWE-257 1 PoC

The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers, with administrative-level access and above, to view the SMTP password for the supplied server. Although this would not be useful for attackers in most cases, if an administrator account becomes compromised this could be useful information to an attacker in a limited environment.

CVE-2024-10098
ApplyOnline Web Windows
2.7
LOW
EPSS
0.3%
2024 1 PoC

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

CVE-2024-8350
Uncanny Groups for LearnDash Web Windows
2.7
LOW
EPSS
0.2%
2024 CWE-862 1 PoC

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.

CVE-2024-10562
Form Maker by 10Web Web Windows
2.7
LOW
EPSS
0.2%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10102
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
2.7
LOW
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-3629
HL Twitter Web Windows
2.4
LOW
EPSS
0.2%
2024 1 PoC

The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack