3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-13825
Email Keep Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12096
Exhibit to WP Gallery Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-50969
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.

CVE-2024-21030
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-50803
Software Genérico Web
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges

CVE-2024-0239
Contact Form 7 Connector Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.

CVE-2024-6651
WordPress File Upload Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
18.5%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6223
Send email only on Reply to My Comment Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-53470
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

CVE-2024-21029
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-52882
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.

CVE-2024-5448
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-27719
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function.

CVE-2024-5081
wp-eMember Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-28276
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.

CVE-2024-22927
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
14.0%
2024 0 PoCs

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2024-3641
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins

CVE-2024-34312
Software Genérico Web
6.1
MEDIUM
EPSS
1.3%
2024 1 PoC

Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

CVE-2024-8056
MM-Breaking News Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-22359
UrbanCode Deploy Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280897.