5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1377
Solidres Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-25309
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.

CVE-2023-7170
EventON-RSVP Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-24195
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.

CVE-2023-23073
Software Genérico Web
6.1
MEDIUM
EPSS
25.7%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

CVE-2023-41703
OX App Suite General
6.1
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

CVE-2023-1596
tagDiv Composer Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-25439
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.

CVE-2023-28850
perspective-editor General
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version 1.5.1 has a patch. As a workaround, one may apply the patch manually.

CVE-2023-30677
Samsung Pass General
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.

CVE-2023-51064
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

CVE-2023-47488
Software Genérico General
6.1
MEDIUM
EPSS
4.6%
2023 3 PoCs

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

CVE-2023-42426
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2023 2 PoCs

Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

CVE-2023-7151
Product Enquiry for WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-23074
Software Genérico Web
6.1
MEDIUM
EPSS
70.9%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

CVE-2023-0769
hiWeb Migration Simple Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

CVE-2023-24529
NetWeaver AS ABAP (Business Server Pages application) Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to hijack a user session, read and modify some sensitive information.

CVE-2023-0479
Print Invoice & Delivery Notes for WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

CVE-2023-31285
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2023 2 PoCs

An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.