6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-56376
REDCap Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.

CVE-2024-45614
puma Web
5.4
MEDIUM
EPSS
0.7%
2024 CWE-639 1 PoC

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on proxy set variables is affected. v6.4.3/v5.6.9 now discards any headers using underscores if the non-underscore version also exists. Effectively, allowing the proxy defined headers to always win. Users are advised to upgrade. Nginx has a underscores_in_headers configuration variable to discard these headers at the proxy level as a mitigation. Any

CVE-2024-57329
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

CVE-2024-20829
Samsung Internet General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

CVE-2024-56377
REDCap Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (which has been injected into all survey fields) is executed, potentially enabling the execution of arbitrary web scripts.

CVE-2024-41447
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.

CVE-2024-55199
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.

CVE-2024-37803
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.

CVE-2024-28339
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-21070
PeopleSoft Enterprise PT PeopleTools Web Database
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Search Framework). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read a

CVE-2024-1274
My Calendar Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)

CVE-2024-13667
Uncode Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-57429
Software Genérico Web
5.4
MEDIUM
EPSS
0.9%
2024 1 PoC

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

CVE-2024-20047
MT6739, MT6768, MT6781, MT6833, MT6853, MT6877, MT6883, MT6885, MT6893, MT8183, MT8188, MT8765, MT8766, MT8768, MT8786, MT8788, MT8791, MT8797 General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587865; Issue ID: ALPS08486807.

CVE-2024-28239
directus Web Database
5.4
MEDIUM
EPSS
0.2%
2024 CWE-601 1 PoC

Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as an open redirect vulnerability as the user tries to log in via the API URL. There's a redirect that is done after successful login via the Auth API GET request to `directus/auth/login/google?redirect=http://malicious-fishing-site.com`. While credentials don't seem to be passed to the attacker site, the user can be phished into clicking a legitimate directus site and be taken to a malicious site made to look like a an error message "Your pas

CVE-2024-6271
Community Events Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

CVE-2024-27703
Software Genérico General
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

CVE-2024-11671
Remote Desktop Manager Database Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-287 1 PoC

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.

CVE-2024-5595
Essential Blocks Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-13722
NagVis Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 3 PoCs

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.