7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-13864
Countdown Timer Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-45187
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 CWE-613 1 PoC

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server

CVE-2024-48032
Featured Posts with Multiple Custom Groups (FPMCG) Web
7.1
HIGH
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) featured-posts-with-multiple-custom-groups-fpmcg allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through <= 4.0.

CVE-2024-29792
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Web ⚡ nuclei
7.1
HIGH
EPSS
14.4%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.93.

CVE-2024-0672
Pz-LinkCard Web Windows
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13571
Post Timeline Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-37261
WP-Lister Lite for Amazon Web ⚡ nuclei
7.1
HIGH
EPSS
17.5%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <= 2.6.16.

CVE-2024-7603
Unified SecOps Platform Web
7.1
HIGH
EPSS
2.4%
2024 CWE-22 1 PoC

Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete directories in the context of root. Was ZDI

CVE-2024-13633
Simple catalogue Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0439
mintplex-labs/anything-llm Web
7.1
HIGH
EPSS
0.2%
2024 CWE-269 1 PoC

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.

CVE-2024-14015
WordPress eCommerce Plugin Web Windows ⚡ nuclei
7.1
HIGH
EPSS
0.4%
2024 1 PoC

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5287
wp-affiliate-platform Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

CVE-2024-13352
Legull Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.8%
2024 1 PoC

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-1938
Chrome General
7.1
HIGH
EPSS
0.4%
2024 1 PoC

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-0551
mintplex-labs/anything-llm General
7.1
HIGH
EPSS
0.6%
2024 CWE-284 1 PoC

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior to the attack. It is worth noting that the deterministic nature of the export name is lower risk as the UI for exporting would start the download at the same time, which once downloaded - deletes the export from the system. The endpoint for exporting should simply be patched to a higher privilege level.

CVE-2024-13569
Front End Users Web Windows ⚡ nuclei
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-40492
Software Genérico General
7.1
HIGH
EPSS
7.7%
2024 1 PoC

Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.

CVE-2024-3903
Add Custom CSS and JS Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in as author and above add Stored XSS payloads via a CSRF attack

CVE-2024-27164
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.1
HIGH
EPSS
0.1%
2024 CWE-259 1 PoC

Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.

CVE-2024-35214
CylanceOPTICS for Windows Windows
7.1
HIGH
EPSS
0.1%
2024 CWE-288 1 PoC

A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.