6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0561
Ultimate Posts Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4602
Embed Peertube Playlist Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5444
Bible Text Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3850
NVR301-04S2-P4 Web ⚡ nuclei
5.4
MEDIUM
EPSS
11.9%
2024 CWE-79 1 PoC

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.

CVE-2024-29413
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant messenger field in the Contact info function.

CVE-2024-24099
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

CVE-2024-8397
webtoffee-gdpr-cookie-consent Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

CVE-2024-21264
PeopleSoft Enterprise CC Common Application Objects Web Database
5.4
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized read access to a subset of PeopleSoft Enterpr

CVE-2024-0820
Jobs for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-54997
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

CVE-2024-5447
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-21286
PeopleSoft Enterprise ELM Enterprise Learning Management Web Database
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM Enterprise Learning Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise ELM Enterprise Learning Management, attacks may significantly impact additional products (scop

CVE-2024-5475
Responsive video embed Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-55239
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.

CVE-2024-37672
Software Genérico General
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.

CVE-2024-12308
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-42918
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.

CVE-2024-38036
Portal for ArcGIS Enterprise Experience Builder Web
5.4
MEDIUM
EPSS
2.7%
2024 CWE-79 1 PoC

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

CVE-2024-55057
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

CVE-2024-2583
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.