13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-33111
Software Genérico Web Networking
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

CVE-2024-9663
CYAN Backup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-30989
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.

CVE-2024-46081
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.

CVE-2024-53364
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.

CVE-2024-0561
Ultimate Posts Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4602
Embed Peertube Playlist Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5444
Bible Text Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3850
NVR301-04S2-P4 Web ⚡ nuclei
5.4
MEDIUM
EPSS
11.9%
2024 CWE-79 1 PoC

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.

CVE-2024-8397
webtoffee-gdpr-cookie-consent Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

CVE-2024-21264
PeopleSoft Enterprise CC Common Application Objects Web Database
5.4
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized read access to a subset of PeopleSoft Enterpr

CVE-2024-0820
Jobs for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-5447
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-21286
PeopleSoft Enterprise ELM Enterprise Learning Management Web Database
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM Enterprise Learning Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise ELM Enterprise Learning Management, attacks may significantly impact additional products (scop

CVE-2024-5475
Responsive video embed Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-55239
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.

CVE-2024-12308
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-42918
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.

CVE-2024-38036
Portal for ArcGIS Enterprise Experience Builder Web
5.4
MEDIUM
EPSS
2.7%
2024 CWE-79 1 PoC

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

CVE-2024-55057
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.