7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40814
macOS General
7.1
HIGH
EPSS
0.0%
2024 1 PoC

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able to bypass Privacy preferences.

CVE-2024-5287
wp-affiliate-platform Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

CVE-2024-33899
Software Genérico General
7.1
HIGH
EPSS
1.0%
2024 1 PoC

RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.

CVE-2024-13571
Post Timeline Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-25007
Ericsson Network Manager General
7.1
HIGH
EPSS
0.1%
2024 CWE-1236 1 PoC

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.

CVE-2024-34469
Software Genérico Web
7.1
HIGH
EPSS
1.2%
2024 1 PoC

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

CVE-2024-0551
mintplex-labs/anything-llm General
7.1
HIGH
EPSS
0.6%
2024 CWE-284 1 PoC

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior to the attack. It is worth noting that the deterministic nature of the export name is lower risk as the UI for exporting would start the download at the same time, which once downloaded - deletes the export from the system. The endpoint for exporting should simply be patched to a higher privilege level.

CVE-2024-56086
Software Genérico General
7.1
HIGH
EPSS
2.6%
2024 1 PoC

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.

CVE-2024-13624
WPMovieLibrary Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.5%
2024 1 PoC

The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-23666
FortiManager Networking
7.1
HIGH
EPSS
8.1%
2024 CWE-602 1 PoC

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.

CVE-2024-13836
WP Login Control Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13881
Link My Posts Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-40783
macOS DevOps
7.1
HIGH
EPSS
0.0%
2024 2 PoCs

The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious application may be able to bypass Privacy preferences.

CVE-2024-47374
LiteSpeed Cache Web ⚡ nuclei
7.1
HIGH
EPSS
26.5%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.

CVE-2024-10483
Simple:Press Forum Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-45178
Software Genérico General
7.1
HIGH
EPSS
1.7%
2024 3 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR syst

CVE-2024-0206
Anti-Malware Engine General
7.1
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files

CVE-2024-13052
Dental Optimizer Patient Generator App Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-47191
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 1 PoC

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

CVE-2024-13057
Dyn Business Panel Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.