3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-12714
Backlink Monitoring Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12725
Clasify Classified Listing Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-30848
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject arbitrary web script or HTML via the version parameter.

CVE-2024-25831
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface.

CVE-2024-31651
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.

CVE-2024-31652
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.

CVE-2024-34452
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

CVE-2024-9934
Wp-ImageZoom Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-25673
Software Genérico Web
6.1
MEDIUM
EPSS
1.2%
2024 2 PoCs

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

CVE-2024-39090
Software Genérico Web
6.1
MEDIUM
EPSS
3.1%
2024 2 PoCs

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to account takeover.

CVE-2024-6892
Journyx (jtime) Web ⚡ nuclei
6.1
MEDIUM
EPSS
7.5%
2024 CWE-81 2 PoCs

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

CVE-2024-48906
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.

CVE-2024-6226
WpStickyBar Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-21032
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-6026
Slider by 10Web Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks

CVE-2024-46079
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.

CVE-2024-5921
GlobalProtect App Web Networking
6.0
MEDIUM
EPSS
0.4%
2024 CWE-295 2 PoCs

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

CVE-2024-24898
kernel Web
6.0
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from 4.19.90-2109.1.0.0108 before 4.19.90-2403.4.0.0244.

CVE-2024-6325
FactoryTalk® System Services (installed via FTPM) Web
6.0
MEDIUM
EPSS
0.0%
2024 CWE-269 2 PoCs

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html  by implementing CIP security and did not update to the versions of the software CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html  and CVE-2022-1161. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html

CVE-2024-27631
Software Genérico Web
6.0
MEDIUM
EPSS
0.4%
2024 3 PoCs

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php