7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-29197
pimcore General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-200 1 PoC

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.

CVE-2024-48705
Software Genérico General
6.5
MEDIUM
EPSS
11.6%
2024 1 PoC

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field

CVE-2024-7817
Misiek Photo Album Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack

CVE-2024-57487
Software Genérico Web
6.5
MEDIUM
EPSS
51.6%
2024 1 PoC

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

CVE-2024-0507
Enterprise Server General
6.5
MEDIUM
EPSS
72.9%
2024 CWE-20 1 PoC

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2024-44765
Software Genérico Cloud
6.5
MEDIUM
EPSS
2.7%
2024 2 PoCs

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.

CVE-2024-47308
Templately General ⚡ nuclei
6.5
MEDIUM
EPSS
35.3%
2024 CWE-862 0 PoCs

Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

CVE-2024-43335
Responsive Blocks – WordPress Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.

CVE-2024-11195
Email Subscription Popup Web Windows
6.4
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-4268
Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor Web Windows
6.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-37457 may be a duplicate of this issue.

CVE-2024-9387
GitLab DevOps Web
6.4
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVE-2024-20831
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVE-2024-22546
Software Genérico General
6.4
MEDIUM
EPSS
0.2%
2024 1 PoC

TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.

CVE-2024-24787
cmd/go General
6.4
MEDIUM
EPSS
2.7%
2024 2 PoCs

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

CVE-2024-49409
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

CVE-2024-4623
Blogmentor – Blog Layouts for Elementor Web Windows
6.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagination_style’ parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-37229 is likely a duplicate of this issue.

CVE-2024-4484
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Web Windows
6.4
MEDIUM
EPSS
3.5%
2024 CWE-79 1 PoC

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-2453
WebAccess/SCADA Database
6.4
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

CVE-2024-11432
SuevaFree Essential Kit Web Windows
6.4
MEDIUM
EPSS
10.7%
2024 CWE-79 1 PoC

The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-8159
DeepFreeze General
6.4
MEDIUM
EPSS
0.1%
2024 CWE-125 1 PoC

Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.