6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-48312
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.

CVE-2024-37764
Software Genérico Web
5.4
MEDIUM
EPSS
7.1%
2024 1 PoC

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

CVE-2024-24397
Software Genérico General
5.4
MEDIUM
EPSS
1.2%
2024 2 PoCs

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

CVE-2024-7846
YITH WooCommerce Ajax Search Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

CVE-2024-22856
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows authenticated attackers to execute unintended queries and disclose sensitive information from DB tables via crafted requests.

CVE-2024-10678
Ultimate Blocks Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6766
shortcodes-ultimate-pro Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-46409
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.

CVE-2024-11695
Firefox General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVE-2024-4940
gradio-app/gradio Web ⚡ nuclei
5.4
MEDIUM
EPSS
7.2%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

CVE-2024-44661
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.

CVE-2024-0719
Tabs Shortcode and Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tabs Shortcode and Widget WordPress plugin through 1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-8092
Accordion Image Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-33527
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.

CVE-2024-53976
Firefox for iOS General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.

CVE-2024-20387
Cisco Firepower Management Center Web Networking
5.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.

CVE-2024-6136
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-48569
Software Genérico Web
5.4
MEDIUM
EPSS
3.1%
2024 2 PoCs

Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/

CVE-2024-3978
WordPress Jitsi Shortcode Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-1142
IQ Server General
5.4
MEDIUM
EPSS
0.3%
2024 CWE-22 1 PoC

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.