1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-4250
EventPrime Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-3041
Autochat Automatic Conversation Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

CVE-2023-3954
MultiParcels Shipping For WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6956
EasyAzon – Amazon Associates Affiliate Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2023 CWE-79 1 PoC

The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘easyazon-cloaking-locale’ parameter in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-1890
Tablesome Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.3%
2023 2 PoCs

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-3671
MultiParcels Shipping For WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-28350
Software Genérico Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine).

CVE-2023-3320
WP Sticky Social Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 1 PoC

The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-31020
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
6.1
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.

CVE-2023-7228
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.

CVE-2023-4826
socialdriver Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.

CVE-2023-1804
Product Catalog Feed by PixelYourSite Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

CVE-2023-1377
Solidres Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0644
Push Notifications for WordPress by PushAssist Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-7203
Smart Forms Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perform unauthorised actions such as deleting entries. The plugin also lacks CSRF checks in some places which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as deleting entries.

CVE-2023-4476
Locatoraid Store Locator Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-6970
WP Recipe Maker Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.4%
2023 CWE-79 0 PoCs

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-2257
Workspace Desktop Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.

CVE-2023-23491
Quick Event Manager WordPress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
11.1%
2023 1 PoC

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

CVE-2023-2023
Custom 404 Pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
80.9%
2023 2 PoCs

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.