3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-21001
Business Intelligence Enterprise Edition Web Database
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of

CVE-2024-29809
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-55056
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

CVE-2024-4756
WP Backpack Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7691
Flaming Forms Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.

CVE-2024-54779
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVE-2024-1333
Responsive Pricing Table Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-29810
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-57273
Software Genérico Web Networking
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.

CVE-2024-13826
Email Keep Web Windows
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-11718
tarteaucitron-wp Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-46077
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

CVE-2024-5004
CM Popup Plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-1306
Smart Forms Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.

CVE-2024-5713
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-37396
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.

CVE-2024-53408
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2024-4372
Carousel Slider Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-28784
QRadar SIEM Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893.

CVE-2024-56377
REDCap Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (which has been injected into all survey fields) is executed, potentially enabling the execution of arbitrary web scripts.