13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-57326
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter.

CVE-2024-10565
Slider by 10Web Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-24035
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 3 PoCs

Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.

CVE-2024-6667
KBucket: Your Curated Content in WordPress Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.

CVE-2024-5079
wp-eMember Web Windows
6.1
MEDIUM
EPSS
2.0%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2024-12282
WordPress连接微博 Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-8907
Chrome Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)

CVE-2024-0420
MapPress Maps for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

CVE-2024-57033
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

CVE-2024-21202
PeopleSoft Enterprise PeopleTools Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result i

CVE-2024-24945
Software Genérico Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

CVE-2024-13431
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2024 CWE-79 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-41810
twisted Web ⚡ nuclei
6.1
MEDIUM
EPSS
67.8%
2024 CWE-79 0 PoCs

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

CVE-2024-38436
SOX 365 Web
6.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-13115
WP Projects Portfolio with Client Testimonials Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-31652
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.

CVE-2024-12275
Canvasflow for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6494
WordPress File Upload Web Windows
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

CVE-2024-6690
wccp-pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

CVE-2024-43112
Firefox for iOS Web
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.