7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-57678
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

CVE-2024-7864
Favicon Generator (CLOSED) Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server

CVE-2024-0365
Fancy Product Designer Web Database Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

CVE-2024-23525
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

CVE-2024-5522
HTML5 Video Player Web Database Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.8%
2024 6 PoCs

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2024-44653
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

CVE-2024-12163
goodlayers-core Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

CVE-2024-1671
Chrome General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-44652
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.

CVE-2024-57241
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
24.1%
2024 2 PoCs

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

CVE-2024-38348
Software Genérico Database
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.

CVE-2024-3963
Giveaways and Contests by RafflePress Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-57487
Software Genérico Web
6.5
MEDIUM
EPSS
51.6%
2024 1 PoC

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

CVE-2024-21509
mysql2 Database
6.5
MEDIUM
EPSS
0.8%
2024 CWE-1321 1 PoC

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

CVE-2024-28418
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

CVE-2024-42849
Software Genérico General
6.5
MEDIUM
EPSS
11.3%
2024 2 PoCs

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

CVE-2024-3749
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user

CVE-2024-21196
MySQL Server Database
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2024-38030
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
67.5%
2024 CWE-200 2 PoCs

Windows Themes Spoofing Vulnerability

CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability