6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-26454
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.

CVE-2024-6408
Slider by 10Web Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2402
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-37799
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

CVE-2024-6727
Data Control Tower (DCT) General
5.4
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application.

CVE-2024-12722
Twitter Bootstrap Collapse aka Accordian Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-26471
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.

CVE-2024-3026
WordPress Button Plugin MaxButtons Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-3965
Pray For Me Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-6754
Social Auto Poster Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post metadata.

CVE-2024-51026
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

CVE-2024-53543
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.

CVE-2024-10482
Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-54795
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.

CVE-2024-5074
wp-eMember Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-53568
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.

CVE-2024-45986
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.

CVE-2024-41968
CC100 0751-9x01 DevOps
5.4
MEDIUM
EPSS
0.6%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

CVE-2024-11670
Remote Desktop Manager Windows
5.4
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.

CVE-2024-0757
Insert or Embed Articulate Content into WordPress Web Windows
5.4
MEDIUM
EPSS
59.1%
2024 2 PoCs

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files