6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-11201
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Web Windows
6.4
MEDIUM
EPSS
9.9%
2024 CWE-79 1 PoC

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_send shortcode in all versions up to, and including, 2.7.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an in

CVE-2024-43018
Software Genérico Web Database
6.4
MEDIUM
EPSS
0.0%
2024 1 PoC

Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for searching users in advanced way in /admin.php?page=user_list.

CVE-2024-4484
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Web Windows
6.4
MEDIUM
EPSS
3.5%
2024 CWE-79 1 PoC

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-2453
WebAccess/SCADA Database
6.4
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

CVE-2024-8159
DeepFreeze General
6.4
MEDIUM
EPSS
0.1%
2024 CWE-125 1 PoC

Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.

CVE-2024-32884
gitoxide Networking
6.4
MEDIUM
EPSS
0.1%
2024 CWE-77 1 PoC

gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by an application whose current working directory contains a malicious file, arbitrary code execution occurs. This is related to the patched vulnerability GHSA-rrjw-j4m2-mf34, but appears less severe due to a greater attack complexity. This issue has been patched in versions 0.35.0,

CVE-2024-10015
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Web Windows
6.4
MEDIUM
EPSS
24.1%
2024 CWE-79 1 PoC

The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-53636
Academia Student Information System Web
6.4
MEDIUM
EPSS
2.9%
2024 CWE-24 2 PoCs

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

CVE-2024-0700
Simple Tweet Web Windows
6.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

The Simple Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tweet this text value in all versions up to, and including, 1.4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-49408
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

CVE-2024-48954
Software Genérico General
6.4
MEDIUM
EPSS
2.5%
2024 2 PoCs

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

CVE-2024-11388
Dino Game – Embed Google Chrome Dinosaur Game in your website Web Windows
6.4
MEDIUM
EPSS
15.7%
2024 CWE-79 1 PoC

The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-11412
Shine PDF Embeder Web Windows
6.4
MEDIUM
EPSS
6.1%
2024 CWE-79 1 PoC

The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-20832
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVE-2024-12020
LogicalDOC Enterprise Web
6.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to induce a victim to perform on-site requests without their knowledge. This vulnerability only affects LogicalDOC Enterprise.

CVE-2024-3333
Essential Addons for Elementor – Popular Elementor Templates & Widgets Web Windows
6.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-31798
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices

CVE-2024-11199
Rescue Shortcodes Web Windows
6.4
MEDIUM
EPSS
13.7%
2024 CWE-79 1 PoC

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progressbar shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-35475
Software Genérico Web Database
6.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

CVE-2024-10592
Mapster WP Maps Web Windows
6.4
MEDIUM
EPSS
41.4%
2024 CWE-80 1 PoC

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.