5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2572
Survey Maker Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-29808
Software Genérico Web
6.1
MEDIUM
EPSS
1.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.

CVE-2023-0733
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.6%
2023 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2023-22035
Scripting Web Database
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Scripting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some

CVE-2023-7167
Persian Fonts Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-4602
Namaste! LMS Web Windows
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 1 PoC

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-51800
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email parameters, new_term function in the tname parameter, and the edit_student function in the name parameter.

CVE-2023-1282
Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

CVE-2023-1324
Easy Forms for Mailchimp Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1465
WP EasyPay Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

CVE-2023-42343
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

CVE-2023-42345
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

CVE-2023-21500
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-415 1 PoC

Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.

CVE-2023-31346
3rd Gen AMD EPYC™ Processors General
6.0
MEDIUM
EPSS
0.0%
2023 2 PoCs

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

CVE-2023-1243
answerdev/answer Web
6.0
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-31355
3rd Gen AMD EPYC™ Processors General
6.0
MEDIUM
EPSS
0.8%
2023 CWE-119 1 PoC

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.

CVE-2023-1239
answerdev/answer Web
6.0
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-21989
VM VirtualBox Database
6.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM Virtu

CVE-2023-21908
Banking Virtual Account Management Web Database
6.0
MEDIUM
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Acco

CVE-2023-42558
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.