6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21501
sanitize-html General
5.3
MEDIUM
EPSS
1.8%
2024 CWE-200 2 PoCs

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

CVE-2024-5120
Event Registration System Database
5.3
MEDIUM
EPSS
0.2%
2024 CWE-89 1 PoC

A vulnerability was found in SourceCodester Event Registration System 1.0. It has been classified as critical. Affected is an unknown function of the file /registrar/?page=registration. The manipulation of the argument e leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265200.

CVE-2024-13144
My-Blog General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the argument editormd-image-file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11121
Lingdang CRM Web Database
5.3
MEDIUM
EPSS
0.2%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this vulnerability is an unknown functionality of the file /crm/WeiXinApp/marketing/index.php?module=Users&action=getActionList. The manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11396
Event Monster – Manager & Ticket Booking Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
54.2%
2024 CWE-359 1 PoC

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

CVE-2024-24789
archive/zip General
5.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVE-2024-6015
Online House Rental System Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument month_of leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268723.

CVE-2024-1526
Hubbub Lite Web Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

CVE-2024-8563
PHP CRUD Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11487
Decoration Management System Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /decoration/admin/btndates_report.php of the component Between Dates Reports. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4106
FAST/TOOLS General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-258 1 PoC

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server R1.01.00 to R1.03.00

CVE-2024-58289
Microweber Web
5.3
MEDIUM
EPSS
0.0%
2024 CWE-79 1 PoC

Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.

CVE-2024-8610
Best House Rental Management System Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 2 PoCs

A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the component New Tenant Page. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10597
CDG Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-10994
Online Institute Management System Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit_user.php. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-0263
Ultra Mini HTTPd Web
5.3
MEDIUM
EPSS
0.2%
2024 CWE-404 3 PoCs

A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249819.

CVE-2024-8151
Interactive Map with Marker Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 2 PoCs

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11662
OpsManage Web Cloud
5.3
MEDIUM
EPSS
0.1%
2024 CWE-502 1 PoC

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deploy_host_vars of the file /apps/api/views/deploy_api.py of the component API Endpoint. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-38828
Spring Web
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

CVE-2024-0579
X2000R General
5.3
MEDIUM
EPSS
0.8%
2024 CWE-77 1 PoC

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.