6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9367
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2024 CWE-770 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVE-2024-0266
Online Lawyer Management System General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-79 2 PoCs

A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the component User Registration. The manipulation of the argument First Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249822 is the identifier assigned to this vulnerability.

CVE-2024-9962
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-12244
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVE-2024-2744
NextGEN Gallery Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-30981
Software Genérico Web Database
4.3
MEDIUM
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.

CVE-2024-3127
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVE-2024-57683
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.

CVE-2024-4886
buddyboss-platform General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

CVE-2024-3147
DedeCMS Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/makehtml_map.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258922 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5272
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.

CVE-2024-31859
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin

CVE-2024-9233
Logo Slider Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-0248
EazyDocs Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 2 PoCs

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

CVE-2024-4475
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack

CVE-2024-0379
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Web Windows
4.3
MEDIUM
EPSS
13.9%
2024 CWE-352 1 PoC

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-45805
opencti Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that can only be accessed by users with access privileges to admin and support information (SETTINGS_SUPPORT). This is due to inadequate access control for support information (http://<opencti_domain>/storage/get/support/UUID/UUID.zip), and that the UUID is available to general users using an attached query (logs query). This vulnerability is fixed in 6.3.0.

CVE-2024-52032
Mattermost Database
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.

CVE-2024-3145
DedeCMS Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/makehtml_js_action.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258920. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-55075
Grocy General
4.3
MEDIUM
EPSS
0.0%
2024 CWE-425 1 PoC

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.