6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-45878
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).

CVE-2024-1956
wpb-show-core Web Windows
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting

CVE-2024-12587
Contact Form Master Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-11607
GTPayment Donations Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-57326
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter.

CVE-2024-10565
Slider by 10Web Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-24035
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 3 PoCs

Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.

CVE-2024-4768
Firefox General
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVE-2024-6667
KBucket: Your Curated Content in WordPress Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.

CVE-2024-5079
wp-eMember Web Windows
6.1
MEDIUM
EPSS
2.0%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2024-26542
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field.

CVE-2024-12282
WordPress连接微博 Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-8907
Chrome Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)

CVE-2024-0420
MapPress Maps for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

CVE-2024-57033
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

CVE-2024-21202
PeopleSoft Enterprise PeopleTools Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result i

CVE-2024-24945
Software Genérico Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

CVE-2024-13431
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2024 CWE-79 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-41810
twisted Web ⚡ nuclei
6.1
MEDIUM
EPSS
67.8%
2024 CWE-79 0 PoCs

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

CVE-2024-38436
SOX 365 Web
6.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')