6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5440
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-10896
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting

CVE-2024-41587
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.

CVE-2024-6668
ProfilePro Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks

CVE-2024-34899
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).

CVE-2024-4232
Digisol Router DG-GR1321 Networking
5.4
MEDIUM
EPSS
2.0%
2024 CWE-256 4 PoCs

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.

CVE-2024-13826
Email Keep Web Windows
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-55056
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

CVE-2024-25041
Cognos Analytics Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780.

CVE-2024-6536
Zephyr Project Manager Web Windows
5.4
MEDIUM
EPSS
52.0%
2024 2 PoCs

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3636
Pinpoint Booking System Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-51032
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.

CVE-2024-44919
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.

CVE-2024-55232
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.

CVE-2024-6074
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-11502
Planning Center Online Giving Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-45177
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent cross-site scripting (XSS) attacks. It was found out that the camera configuration is vulnerable to a persistent cross-site scripting attack due to insufficient user input validation.

CVE-2024-29507
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

CVE-2024-3752
Crelly Slider Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4094
Simple Share Buttons Adder Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed