6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0250
Analytics Insights for Google Analytics 4 (AIWP) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.2%
2024 1 PoC

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-21021
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-10103
MailPoet Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

CVE-2024-57427
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2024 1 PoC

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.

CVE-2024-5729
Simple AL Slider Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-56916
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits a Configuration History version or attempts to Add a new version, the XSS payload will trigger.

CVE-2024-22551
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

CVE-2024-50807
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.

CVE-2024-36392
DeviceHub Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-39090
Software Genérico Web
6.1
MEDIUM
EPSS
3.1%
2024 2 PoCs

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to account takeover.

CVE-2024-13218
Fast Tube Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-11044
automatic1111/stable-diffusion-webui General ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-25435
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.

CVE-2024-31847
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization.

CVE-2024-55040
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.

CVE-2024-23995
Software Genérico DevOps Web
6.1
MEDIUM
EPSS
1.5%
2024 2 PoCs

Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.

CVE-2024-41502
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the "Pessoas" (persons) section when creating or editing either a legal or a natural person.

CVE-2024-27162
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.1
MEDIUM
EPSS
4.0%
2024 CWE-79 1 PoC

Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. An attacker can steal the cookie of an admin user. As for the affected products/models/versions, see the reference URL.

CVE-2024-3692
Gutenverse Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-11846
TravelTour Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin