5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-44012
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
15.2%
2023 0 PoCs

Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.

CVE-2023-39366
cacti Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The `data_sources.php` script displays the data source management information (e.g. data source path, polling configuration etc.) for different data visualizations of the _cacti_ app. CENSUS found that an adversary that is able to c

CVE-2023-49973
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.

CVE-2023-3523
gpac/gpac General
6.1
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-0878
nuxt/framework Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.

CVE-2023-0448
WP Helper Lite Wordpress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
27.7%
2023 1 PoC

The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.

CVE-2023-0738
OrangeScrum General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.

CVE-2023-4819
Shared Files Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

CVE-2023-1011
AI ChatBot Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.

CVE-2023-24522
NetWeaver AS ABAP (BSP Framework) General
6.1
MEDIUM
EPSS
1.4%
2023 CWE-79 1 PoC

Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.

CVE-2023-49984
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2023-0214
Secure Web Gateway (SWG) Web
6.1
MEDIUM
EPSS
3.9%
2023 CWE-79 1 PoC

A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG.

CVE-2023-39515
cacti Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by administrative cacti accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_debug.php` displays data source related debugging information such as _data source paths, polling settings, meta-data on the data source_. _CENSUS_ found that an adversary that is able to configure a malicious data

CVE-2023-26123
raysan5/raylib Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Versions of the package raysan5/raylib before 4.5.0 are vulnerable to Cross-site Scripting (XSS) such that the SetClipboardText API does not properly escape the ' character, allowing attacker-controlled input to break out of the string and execute arbitrary JavaScript via emscripten_run_script function. **Note:** This vulnerability is present only when compiling raylib for PLATFORM_WEB. All the other Desktop/Mobile/Embedded platforms are not affected.

CVE-2023-0236
Tutor LMS Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
20.1%
2023 1 PoC

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-5192
pimcore/demo General
6.1
MEDIUM
EPSS
0.0%
2023 CWE-1049 1 PoC

Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.

CVE-2023-26777
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.

CVE-2023-4603
Star CloudPRNT for WooCommerce Web Cloud Windows
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 2 PoCs

The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printersettings' parameter in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-22055
JD Edwards EnterpriseOne Tools Web Database
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized u