6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46605
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

CVE-2024-3966
Pray For Me Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that trigger when an admin visits the Prayer Requests in the WP Admin

CVE-2024-12096
Exhibit to WP Gallery Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-50803
Software Genérico Web
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges

CVE-2024-22359
UrbanCode Deploy Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280897.

CVE-2024-33305
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.

CVE-2024-10858
Jetpack Web Windows
6.1
MEDIUM
EPSS
0.0%
2024 2 PoCs

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

CVE-2024-3478
Herd Effects Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

CVE-2024-24816
ckeditor4 Web
6.1
MEDIUM
EPSS
39.8%
2024 CWE-79 1 PoC

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.

CVE-2024-13603
Wise Forms Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.

CVE-2024-41693
Mashov Web
6.1
MEDIUM
EPSS
0.4%
2024 CWE-80 1 PoC

Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVE-2024-57529
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.

CVE-2024-33371
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.

CVE-2024-35582
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.

CVE-2024-50861
Software Genérico Web
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

CVE-2024-45247
Sonarr General
6.1
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2024-3276
Lightbox & Modal Popup WordPress Plugin Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13727
MemberSpace Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

CVE-2024-41503
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function.

CVE-2024-28803
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter