13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-6715
Ditty Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

CVE-2024-13822
Photo Contest | Competition | Video Contest Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-57026
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.

CVE-2024-21035
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-22637
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

CVE-2024-52762
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.6%
2024 0 PoCs

A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.

CVE-2024-46605
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

CVE-2024-3966
Pray For Me Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that trigger when an admin visits the Prayer Requests in the WP Admin

CVE-2024-12096
Exhibit to WP Gallery Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-50803
Software Genérico Web
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges

CVE-2024-22359
UrbanCode Deploy Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280897.

CVE-2024-33305
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.

CVE-2024-10858
Jetpack Web Windows
6.1
MEDIUM
EPSS
0.0%
2024 2 PoCs

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

CVE-2024-3478
Herd Effects Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

CVE-2024-24816
ckeditor4 Web
6.1
MEDIUM
EPSS
39.8%
2024 CWE-79 1 PoC

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.

CVE-2024-13603
Wise Forms Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.

CVE-2024-41693
Mashov Web
6.1
MEDIUM
EPSS
0.4%
2024 CWE-80 1 PoC

Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVE-2024-33371
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.

CVE-2024-35582
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.

CVE-2024-50861
Software Genérico Web
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.