7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2403
Remote Desktop Manager Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory.

CVE-2024-9681
curl Web
5.9
MEDIUM
EPSS
0.7%
2024 5 PoCs

When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this p

CVE-2024-27141
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-776 1 PoC

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.

CVE-2024-5573
Easy Table of Contents Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-11357
goodlayers-core Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5075
wp-eMember Web Windows
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-41738
TXSeries for Multiplatforms Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-598 1 PoC

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

CVE-2024-28065
Software Genérico General
5.9
MEDIUM
EPSS
0.0%
2024 2 PoCs

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

CVE-2024-24454
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-24553
Bludit General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-916 1 PoC

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

CVE-2024-32045
Mattermost General
5.9
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of.

CVE-2024-2749
VikBooking Hotel Booking Engine & PMS Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.

CVE-2024-4096
Responsive Tabs Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

CVE-2024-50383
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be affected.)

CVE-2024-43292
Envo's Elementor Templates & Widgets for WooCommerce Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates & Widgets for WooCommerce: from n/a through 1.4.16.

CVE-2024-9836
RSS Feed Widget Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-2310
WP Google Review Slider Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3964
Product Enquiry for WooCommerce Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-37798
Software Genérico Web
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.

CVE-2024-10104
Jobs for WordPress Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks