6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1333
Responsive Pricing Table Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5713
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-28784
QRadar SIEM Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893.

CVE-2024-5644
Tournamatch Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-25434
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.

CVE-2024-10892
Cost Calculator Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-44450
Software Genérico General
5.4
MEDIUM
EPSS
1.1%
2024 2 PoCs

Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.

CVE-2024-3288
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.8%
2024 1 PoC

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3236
Popup Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-39123
Software Genérico Web
5.4
MEDIUM
EPSS
16.4%
2024 2 PoCs

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.

CVE-2024-10504
Contact Form, Survey, Quiz & Popup Form Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2024-0589
Remote Desktop Manager Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

CVE-2024-46606
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

CVE-2024-2369
Page Builder Gutenberg Blocks Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-21494
github.com/greenpau/caddy-security Web
5.4
MEDIUM
EPSS
0.0%
2024 CWE-290 2 PoCs

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.

CVE-2024-33209
Software Genérico Web
5.4
MEDIUM
EPSS
6.2%
2024 1 PoC

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

CVE-2024-10818
JSFiddle Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13101
WP MediaTagger Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5728
Animated AL List Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-54772
Software Genérico Networking
5.4
MEDIUM
EPSS
2.0%
2024 2 PoCs

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.