13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-13633
Simple catalogue Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13052
Dental Optimizer Patient Generator App Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0249
Advanced Schedule Posts Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2024-5151
SULly Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5422
utnserver Pro Web
7.1
HIGH
EPSS
0.1%
2024 CWE-400 2 PoCs

An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2024-27168
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
7.1
HIGH
EPSS
0.0%
2024 CWE-798 1 PoC

It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.

CVE-2024-0439
mintplex-labs/anything-llm Web
7.1
HIGH
EPSS
0.2%
2024 CWE-269 1 PoC

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.

CVE-2024-13875
WP-PManager Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-29138
Restrict User Access – Membership Plugin with Force Web ⚡ nuclei
7.1
HIGH
EPSS
11.6%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joachim Jensen Restrict User Access – Membership Plugin with Force restrict-user-access.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through <= 2.5.

CVE-2024-13874
Feedify Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13571
Post Timeline Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-34231
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.

CVE-2024-4290
Sailthru Triggermail Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-22198
nginx-ui Web
7.1
HIGH
EPSS
16.0%
2024 CWE-77 1 PoC

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sending a request to the API. This issue may lead to authenticated remote code execution, privilege escalation, and information disclosure. This vulnerability has been patched in version 2.0.0.beta.9.

CVE-2024-4531
Business Card Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

CVE-2024-29137
Tourfic Web ⚡ nuclei
7.1
HIGH
EPSS
16.9%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

CVE-2024-55545
IAP-420 Web
7.1
HIGH
EPSS
0.4%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2024-0672
Pz-LinkCard Web Windows
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13574
XV Random Quotes Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12749
Competition Form Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.