7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21099
Business Intelligence Enterprise Edition Web Database
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visualization). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:

CVE-2024-9889
ElementInvader Addons for Elementor Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected posts, pages, and Elementor templates that they should not have access to.

CVE-2024-42338
CyberArk Identity Management General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-8322
Endpoint Manager General
4.3
MEDIUM
EPSS
1.6%
2024 CWE-1390 1 PoC

Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

CVE-2024-12709
Bulk Me Now! Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-43105
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2024 CWE-400 1 PoC

Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.

CVE-2024-6398
Secure Web Gateway General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the

CVE-2024-7984
Joy Of Text Lite Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-55058
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

CVE-2024-3086
Emergency Ambulance Hiring Portal Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability classified as problematic was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The manipulation of the argument searchdata leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258679.

CVE-2024-4382
CB (legacy) Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

CVE-2024-45250
iClock v3.1-168 General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-25270
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.

CVE-2024-50052
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2024 CWE-862 1 PoC

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

CVE-2024-37830
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.

CVE-2024-10241
Mattermost Database
4.3
MEDIUM
EPSS
0.4%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

CVE-2024-23298
Xcode General
4.3
MEDIUM
EPSS
1.5%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

CVE-2024-2429
Salon booking system Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12148
Server General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-863 1 PoC

Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

CVE-2024-0861
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2024 CWE-425 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.