6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-4483
Email Encoder Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-54998
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

CVE-2024-37394
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.

CVE-2024-42406
Mattermost General
5.4
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.

CVE-2024-35468
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

CVE-2024-6859
WP MultiTasking Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-22855
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

CVE-2024-29809
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-54779
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVE-2024-28435
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

CVE-2024-36441
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.

CVE-2024-29810
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-46077
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

CVE-2024-37396
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.

CVE-2024-53408
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2024-48119
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

CVE-2024-4270
SVGMagic Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-13097
WP Finance Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6533
Directus Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.