7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1588
SendPress Newsletters Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-52794
discourse General
6.8
MEDIUM
EPSS
0.5%
2024 CWE-79 1 PoC

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-12657
Advanced SystemCare Utimate General
6.8
MEDIUM
EPSS
0.1%
2024 CWE-476 2 PoCs

A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5077
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-10709
YaDisk Files Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-1231
CM Download Manager Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack

CVE-2024-30988
Software Genérico Web Database
6.8
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar.

CVE-2024-0145
nvJPEG2000 General
6.8
MEDIUM
EPSS
0.1%
2024 CWE-122 1 PoC

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to code execution and data tampering.

CVE-2024-5676
IP150 Internet Module Web
6.8
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.

CVE-2024-22894
Software Genérico General
6.8
MEDIUM
EPSS
3.3%
2024 1 PoC

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

CVE-2024-2640
Watu Quiz Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2024-34519
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2024 1 PoC

Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an auto-login user, data disclosure may occur. Access control can be bypassed when there is a shared dashboard, and its auto-login user has privileges that a dashboard visitor should not have.

CVE-2024-12656
USB over Network General
6.8
MEDIUM
EPSS
0.1%
2024 CWE-476 2 PoCs

A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-30987
Software Genérico Web Database
6.8
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.

CVE-2024-4305
Post Grid Gutenberg Blocks and WordPress Blog Plugin Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3710
Image Photo Gallery Final Tiles Grid Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2024-37600
Software Genérico Web
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address, an attacker can connect via the internal network to the Service Broker service. With prepared HTTP requests, an attacker can cause the Service-Broker service to fail.

CVE-2024-13347
Essential WP Real Estate Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2024-40893
Box Software Networking Cloud
6.8
MEDIUM
EPSS
1.6%
2024 CWE-78 1 PoC

Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software versions before 1.979. A physically close attacker that is authenticated to the Bluetooth Low-Energy (BTLE) interface can use the network configuration service to inject commands in various configuration parameters including networkConfig.Interface.Phy.Eth0.Extra.PingTestIP, networkConfig.Interface.Phy.Eth0.Extra.DNSTestDomain, and networkConfig.Interface.Phy.Eth0.Gateway6. Additionally, because the configuration can be synced to the Firewalla cloud, the attacker may be able to pers

CVE-2024-5430
GitLab DevOps
6.8
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.