7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2822
DedeCMS Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/vote_edit.php. The manipulation of the argument aid leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257709 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1279
Paid Memberships Pro Web Windows
4.3
MEDIUM
EPSS
0.5%
2024 1 PoC

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

CVE-2024-11842
DN Shipping by Weight for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1888
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server

CVE-2024-13420
Benaa Framework Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-94 1 PoC

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.

CVE-2024-51464
i General
4.3
MEDIUM
EPSS
0.4%
2024 CWE-288 2 PoCs

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.

CVE-2024-23493
Mattermost Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 

CVE-2024-8908
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-1564
wp-schema-pro Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

CVE-2024-2908
Call Now Button Web Windows
4.3
MEDIUM
EPSS
2.5%
2024 1 PoC

The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-45250
iClock v3.1-168 General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-4183
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-400 1 PoC

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.

CVE-2024-29215
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook task command.

CVE-2024-3686
DedeCMS Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-24 1 PoC

A vulnerability has been found in DedeCMS 5.7.112-UTF8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file update_guide.php. The manipulation of the argument files leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260473 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-47401
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-770 1 PoC

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.

CVE-2024-54679
Software Genérico Database
4.3
MEDIUM
EPSS
2.2%
2024 1 PoC

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVE-2024-0695
Easy Chat Server Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-404 4 PoCs

A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of the component HTTP GET Request Handler. The manipulation of the argument USERNAME leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251480. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-20856
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

CVE-2024-0356
ssm_shiro_blog General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles of the component Backend. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250123.

CVE-2024-39839
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.