6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-11672
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

CVE-2024-2639
Wholesale Inventory Management System General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-384 1 PoC

A vulnerability was found in Bdtask Wholesale Inventory Management System up to 20240311. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257245 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-33525
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational unit" feature in ILIAS 7.20 to 7.29 and ILIAS 8.4 to 8.10 as well as ILIAS 9.0 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.

CVE-2024-7976
Chrome General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-55417
Software Genérico General ⚡ nuclei
4.3
MEDIUM
EPSS
23.0%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

CVE-2024-2822
DedeCMS Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/vote_edit.php. The manipulation of the argument aid leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257709 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-54679
Software Genérico Database
4.3
MEDIUM
EPSS
2.2%
2024 1 PoC

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVE-2024-4382
CB (legacy) Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

CVE-2024-1330
kadence-blocks-pro Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

CVE-2024-9963
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-49411
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.

CVE-2024-7862
blogintroduction-wordpress-plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-34061
changedetection.io Web ⚡ nuclei
4.3
MEDIUM
EPSS
27.7%
2024 CWE-79 0 PoCs

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in the application. A reflected XSS vulnerability happens when the user input from a URL or POST data is reflected on the page without being stored, thus allowing the attacker to inject malicious content. This issue has been addressed in version 0.45.22. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-21206
Oracle Enterprise Command Center Framework Web Database
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2024-7020
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-3163
Easy Property Listings Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-9583
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-862 1 PoC

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.

CVE-2024-8157
Alphabetical List Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-11842
DN Shipping by Weight for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12709
Bulk Me Now! Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.