5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27294
OpenCATS Web
5.4
MEDIUM
EPSS
0.5%
2023 1 PoC

Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar event, which would then be executed in other users' browsers if they browse to that event. This could result in stealing session tokens from users with higher permission levels or forcing users to make actions without their knowledge.

CVE-2023-1315
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
10.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-43719
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SHIPPING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0373
Lightweight Accordion Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-43343
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.

CVE-2023-21921
Health Sciences InForm Web Database
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data. CVSS

CVE-2023-29049
OX App Suite General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a trusted domain. User input for this widget is now sanitized to avoid malicious content the be processed. No publicly available exploits are known.

CVE-2023-30453
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter.

CVE-2023-24721
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2023-43733
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-43717
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-27775
Software Genérico General
5.4
MEDIUM
EPSS
0.5%
2023 1 PoC

A stored HTML injection vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary code via a crafted payload.

CVE-2023-6710
JBoss Core Services for RHEL 8 Web
5.4
MEDIUM
EPSS
1.1%
2023 CWE-79 2 PoCs

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.

CVE-2023-0660
Smart Slider 3 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0094
UpQode Google Maps Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1956
Online Computer and Laptop Store Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_img of the component Image Handler. The manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225343.

CVE-2023-24204
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

CVE-2023-28664
Meta Data and Taxonomies Filter WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user.

CVE-2023-29506
xwiki-platform General ⚡ nuclei
5.4
MEDIUM
EPSS
11.5%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

CVE-2023-0362
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.