5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4270
Min Max Control Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-27000
Software Genérico General
6.1
MEDIUM
EPSS
0.8%
2023 1 PoC

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).

CVE-2023-3292
grid-kit-premium Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-22432
web2py General ⚡ nuclei
6.1
MEDIUM
EPSS
40.8%
2023 1 PoC

Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

CVE-2023-23078
Software Genérico Web
6.1
MEDIUM
EPSS
26.2%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

CVE-2023-21482
Samsung Camera General
6.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.

CVE-2023-24192
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.

CVE-2023-0334
ShortPixel Adaptive Images Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.1%
2023 1 PoC

The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin

CVE-2023-24191
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.

CVE-2023-2399
QuBot Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 2 PoCs

The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.

CVE-2023-0410
builderio/qwik Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.

CVE-2023-1420
Ajax Search Lite Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-40819
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

CVE-2023-4250
EventPrime Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-3041
Autochat Automatic Conversation Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

CVE-2023-6956
EasyAzon – Amazon Associates Affiliate Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2023 CWE-79 1 PoC

The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘easyazon-cloaking-locale’ parameter in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-39683
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher claims issue is present in all versions prior and later than tested version.

CVE-2023-28350
Software Genérico Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine).

CVE-2023-1804
Product Catalog Feed by PixelYourSite Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

CVE-2023-2257
Workspace Desktop Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.