6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1756
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name

CVE-2024-56114
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.

CVE-2024-4210
GitLab DevOps
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVE-2024-57494
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.

CVE-2024-44641
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

CVE-2024-6852
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1309
Niagara Framework Windows
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 3 PoCs

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.

CVE-2024-3840
Chrome General
6.5
MEDIUM
EPSS
0.2%
2024 2 PoCs

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-1930
dnf5daemon-server Networking
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.

CVE-2024-27659
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-29272
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
89.4%
2024 1 PoC

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

CVE-2024-57170
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality.

CVE-2024-35539
Software Genérico General
6.5
MEDIUM
EPSS
3.0%
2024 1 PoC

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

CVE-2024-29156
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

CVE-2024-9379
🔥 KEV CSA (Cloud Services Appliance) Database Cloud
6.5
MEDIUM
EPSS
81.7%
2024 CWE-89 1 PoC

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVE-2024-57676
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

CVE-2024-28418
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

CVE-2024-6853
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-44657
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.

CVE-2024-10219
GitLab DevOps Web
6.5
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.