CVE-2024-6118

CVE-2024-6118

Título es
CVE-2024-6118

Lun, 05/08/2024 – 05:15

Tipo
CWE-256

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-6118

Descripción en
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-6117

CVE-2024-6117

Título es
CVE-2024-6117

Lun, 05/08/2024 – 05:15

Tipo
CWE-434

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-6117

Descripción en
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-41889

CVE-2024-41889

Título es
CVE-2024-41889

Lun, 05/08/2024 – 05:15

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-41889

Descripción en
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-41720

CVE-2024-41720

Título es
CVE-2024-41720

Lun, 05/08/2024 – 05:15

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-41720

Descripción en
Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the configuration of the device.

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-2232

CVE-2024-2232

Título es
CVE-2024-2232

Lun, 05/08/2024 – 06:16

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-2232

Descripción en
The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-6710

CVE-2024-6710

Título es
CVE-2024-6710

Lun, 05/08/2024 – 06:16

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-6710

Descripción en
The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-6498

CVE-2024-6498

Título es
CVE-2024-6498

Lun, 05/08/2024 – 06:16

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-6498

Descripción en
The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-6270

CVE-2024-6270

Título es
CVE-2024-6270

Lun, 05/08/2024 – 06:16

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-6270

Descripción en
The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-5081

CVE-2024-5081

Título es
CVE-2024-5081

Lun, 05/08/2024 – 06:16

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-5081

Descripción en
The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off

CVE-2024-3636

CVE-2024-3636

Título es
CVE-2024-3636

Lun, 05/08/2024 – 06:16

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2024-3636

Descripción en
The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

05/08/2024
05/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Enviar en el boletín
Off