38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-6224
Send email only on Reply to My Comment Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2022-22405
Aspera Faspex Web
5.9
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 222576.

CVE-2024-13113
Countdown Timer for Elementor Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2024-27623
Software Genérico Web
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

CVE-2023-27624
Redirect After Login Web ⚡ nuclei
5.9
MEDIUM
EPSS
0.7%
2023 CWE-79 0 PoCs

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions.

CVE-2024-1743
WooCommerce Customers Manager Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-3782
Software Genérico Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-400 1 PoC

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response

CVE-2024-12289
Boundary Web
5.9
MEDIUM
EPSS
0.4%
2024 CWE-460 1 PoC

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.

CVE-2024-10076
Jetpack Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks

CVE-2024-2118
Social Media Share Buttons & Social Sharing Icons Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5604
Bug Library Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3113
FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3472
Modal Window Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-4752
EventON Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6243
HTML Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

CVE-2020-8553
ingress-nginx DevOps Web
5.9
MEDIUM
EPSS
0.5%
2020 CWE-73 1 PoC

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.

CVE-2023-1212
phpipam/phpipam Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.

CVE-2024-10105
Job Postings Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6487
Inline Related Posts Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2020-2574
MySQL Server Web Database
5.9
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.46 and prior, 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).