6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5808
WP Ajax Contact Form Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-0880
qdbcrm Web
4.3
MEDIUM
EPSS
0.3%
2024 CWE-352 1 PoC

A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/edit?id=2 of the component Password Reset. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252032. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-21048
Web Applications Desktop Integrator Web Database
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

CVE-2024-0967
ArcSight Enterprise Security Manager General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

CVE-2024-55231
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.

CVE-2024-20894
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.

CVE-2024-7019
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-3194
MailCleaner General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-262310 is the identifier assigned to this vulnerability.

CVE-2024-21249
PeopleSoft Enterprise FIN Expenses Web Database
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN Expenses accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2024-8050
Custom Author Base Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-11373
Connexion Logs Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-8398
Simple Nav Archives Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1901
Server General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.

CVE-2024-1204
Meta Box Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.

CVE-2024-4477
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting

CVE-2024-43780
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.

CVE-2024-1887
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export. 

CVE-2024-7820
ILC Thickbox Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-45250
iClock v3.1-168 General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-49421
Quick Share Agent General
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.