6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-51423
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code via the class parameter.

CVE-2024-7687
AZIndex Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-0711
Buttons Shortcode and Widget Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-4704
Contact Form 7 Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

CVE-2024-46452
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to a malicious site via a crafted URL.

CVE-2024-11141
Sailthru Triggermail Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13328
Giga Messenger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-31204
mailcow-dockerized DevOps Web
6.1
MEDIUM
EPSS
4.6%
2024 CWE-79 1 PoC

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability resides in the exception handling mechanism, specifically when not operating in DEV_MODE. The system saves exception details into a session array without proper sanitization or encoding. These details are later rendered into HTML and executed in a JavaScript block within the user's browser, without adequate escaping of HTML entities. This flaw allows for Cross-Site Scripting (XSS) attacks, where attackers ca

CVE-2024-41591
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

CVE-2024-25976
HAWKI Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 CWE-79 2 PoCs

When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the victim's browser. This is due to a fault in the file login.php where the content of "$_SERVER['PHP_SELF']" is reflected into the HTML of the website. Hence the attacker does not need a valid account in order to exploit this issue.

CVE-2024-34452
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

CVE-2024-12725
Clasify Classified Listing Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-31648
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.

CVE-2024-42900
Software Genérico Web Database
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.

CVE-2024-6715
Ditty Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

CVE-2024-13822
Photo Contest | Competition | Video Contest Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-57026
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.

CVE-2024-21035
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-22637
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

CVE-2024-52762
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.6%
2024 0 PoCs

A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.