1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13052
Dental Optimizer Patient Generator App Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6529
Ultimate Classified Listings Web Windows
7.1
HIGH
EPSS
52.4%
2024 2 PoCs

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13352
Legull Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.8%
2024 1 PoC

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12638
Bulk Me Now! Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.2%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13863
Stylish Google Sheet Reader 4.0 Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13878
SpotBot Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-37259
The Ultimate WordPress Toolkit – WP Extended Web Windows ⚡ nuclei
7.1
HIGH
EPSS
11.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through <= 2.4.7.

CVE-2024-13880
My Quota Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13668
WordPress Activity O Meter Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2024-12749
Competition Form Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13055
Dyn Business Panel Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.2%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-5287
wp-affiliate-platform Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

CVE-2024-13626
VR-Frases (collect & share quotes) Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13875
WP-PManager Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13574
XV Random Quotes Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13862
S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) Web Cloud Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13625
Tube Video Ads Lite Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.7%
2024 1 PoC

The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13329
Solidres Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-35214
CylanceOPTICS for Windows Windows
7.1
HIGH
EPSS
0.1%
2024 CWE-288 1 PoC

A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.