13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-13864
Countdown Timer Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13569
Front End Users Web Windows ⚡ nuclei
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-30875
Software Genérico Web
7.1
HIGH
EPSS
19.8%
2024 1 PoC

Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQuery UI.

CVE-2024-13881
Link My Posts Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13632
WP Extra Fields Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12019
LogicalDOC Community Web
7.1
HIGH
EPSS
0.2%
2024 CWE-23 1 PoC

The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read’ and ‘download’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to read the contents of any file available within the privileges of the system user running the application.

CVE-2024-13884
Limit Bio Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13330
JustRows free Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12878
Custom Block Builder Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.7%
2024 1 PoC

The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-56917
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVE-2024-12708
Bulk Me Now! Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13863
Stylish Google Sheet Reader 4.0 Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-41357
Software Genérico Web
7.1
HIGH
EPSS
2.2%
2024 1 PoC

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

CVE-2024-55546
IAP-420 Web
7.1
HIGH
EPSS
0.2%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2024-13668
WordPress Activity O Meter Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2024-13625
Tube Video Ads Lite Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.7%
2024 1 PoC

The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12321
WC Affiliate Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13055
Dyn Business Panel Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.2%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13880
My Quota Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-7603
Unified SecOps Platform Web
7.1
HIGH
EPSS
2.4%
2024 CWE-22 1 PoC

Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete directories in the context of root. Was ZDI