6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34327
Software Genérico Database
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.

CVE-2024-57487
Software Genérico Web
6.5
MEDIUM
EPSS
51.6%
2024 1 PoC

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

CVE-2024-23525
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

CVE-2024-1747
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.

CVE-2024-33860
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.

CVE-2024-21205
Oracle Service Bus Web Database
6.5
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-6412
HTML Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-2756
PHP Web
6.5
MEDIUM
EPSS
7.7%
2024 CWE-20 1 PoC

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.

CVE-2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
20.0%
2024 CWE-862 0 PoCs

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.

CVE-2024-6138
Secure Copy Content Protection and Content Locking Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12558
WP BASE Booking of Appointments, Services and Events Web Windows
6.5
MEDIUM
EPSS
30.8%
2024 CWE-862 2 PoCs

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password.

CVE-2024-30851
Software Genérico Web
6.5
MEDIUM
EPSS
69.2%
2024 1 PoC

Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.php component.

CVE-2024-47893
Graphics DDK General
6.5
MEDIUM
EPSS
0.3%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.

CVE-2024-57679
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

CVE-2024-1307
Smart Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions

CVE-2024-13369
Tour Master - Tour Booking, Travel, Hotel Web Database Windows
6.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-21533
ggit Web
6.5
MEDIUM
EPSS
0.0%
2024 CWE-88 2 PoCs

All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and the file on disk to clone to. The library does not sanitize for user input or validate a given URL scheme, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.

CVE-2024-41972
CC100 0751-9x01 General
6.5
MEDIUM
EPSS
0.3%
2024 CWE-35 1 PoC

A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.

CVE-2024-8286
webtoffee-gdpr-cookie-consent Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks