7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28999
SolarWinds Platform General
6.4
MEDIUM
EPSS
6.5%
2024 CWE-362 1 PoC

The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

CVE-2024-48952
Software Genérico Web
6.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.

CVE-2024-11201
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Web Windows
6.4
MEDIUM
EPSS
9.9%
2024 CWE-79 1 PoC

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_send shortcode in all versions up to, and including, 2.7.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an in

CVE-2024-0508
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Web Windows
6.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up to, and including, 2.10.27 due to insufficient input sanitization and output escaping on the user supplied link URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-45965
Contao Web
6.4
MEDIUM
EPSS
0.3%
2024 CWE-434 1 PoC

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

CVE-2024-43018
Software Genérico Web Database
6.4
MEDIUM
EPSS
0.0%
2024 1 PoC

Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for searching users in advanced way in /admin.php?page=user_list.

CVE-2024-49408
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

CVE-2024-48954
Software Genérico General
6.4
MEDIUM
EPSS
2.5%
2024 2 PoCs

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

CVE-2024-11388
Dino Game – Embed Google Chrome Dinosaur Game in your website Web Windows
6.4
MEDIUM
EPSS
15.7%
2024 CWE-79 1 PoC

The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-4665
EventPrime Web Windows
6.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

CVE-2024-6485
Bootstrap Web
6.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

CVE-2024-3563
Genesis Blocks Web Windows
6.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-3901 is a duplicate of this issue.

CVE-2024-51430
Software Genérico Web
6.4
MEDIUM
EPSS
4.2%
2024 1 PoC

Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name parameter on the diagnostic/add-test.php component.

CVE-2024-11412
Shine PDF Embeder Web Windows
6.4
MEDIUM
EPSS
6.1%
2024 CWE-79 1 PoC

The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-8105
vz2694g General
6.4
MEDIUM
EPSS
0.0%
2024 1 PoC

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

CVE-2024-20880
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.3%
2024 1 PoC

Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

CVE-2024-31798
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices

CVE-2024-43788
webpack Web
6.4
MEDIUM
EPSS
1.8%
2024 CWE-79 1 PoC

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have discovered a DOM Clobbering vulnerability in Webpack’s `AutoPublicPathRuntimeModule`. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name` attribute) are present. Real-world exploitation of this gadget has been observed in the Canvas LMS

CVE-2024-7703
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Web Windows
6.4
MEDIUM
EPSS
44.7%
2024 CWE-79 1 PoC

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.37 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2024-20832
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.