13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-8090
JavaScript Logic Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-3637
Responsive Contact Form Builder & Lead Generation Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-28436
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.

CVE-2024-21022
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-44655
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.

CVE-2024-13868
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-29029
memos Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.9%
2024 CWE-918 0 PoCs

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.

CVE-2024-46300
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

CVE-2024-7687
AZIndex Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-0711
Buttons Shortcode and Widget Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-4704
Contact Form 7 Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

CVE-2024-11141
Sailthru Triggermail Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13328
Giga Messenger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-31204
mailcow-dockerized DevOps Web
6.1
MEDIUM
EPSS
4.6%
2024 CWE-79 1 PoC

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability resides in the exception handling mechanism, specifically when not operating in DEV_MODE. The system saves exception details into a session array without proper sanitization or encoding. These details are later rendered into HTML and executed in a JavaScript block within the user's browser, without adequate escaping of HTML entities. This flaw allows for Cross-Site Scripting (XSS) attacks, where attackers ca

CVE-2024-41591
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

CVE-2024-25976
HAWKI Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 CWE-79 2 PoCs

When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the victim's browser. This is due to a fault in the file login.php where the content of "$_SERVER['PHP_SELF']" is reflected into the HTML of the website. Hence the attacker does not need a valid account in order to exploit this issue.

CVE-2024-34452
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

CVE-2024-12725
Clasify Classified Listing Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-31648
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.

CVE-2024-42900
Software Genérico Web Database
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.