6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-8854
Polls CP Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

CVE-2024-20377
Cisco Firepower Management Center Web Networking
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker could exploit this vulnerability by by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browse

CVE-2024-7008
Calibre Web ⚡ nuclei
5.4
MEDIUM
EPSS
13.4%
2024 CWE-79 1 PoC

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

CVE-2024-1746
Testimonial Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-53975
Firefox for iOS Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.

CVE-2024-6710
Ditty Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2024-55570
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to increase their privileges by sending a single HTTP PUT request with rolename=Administrator, aka incorrect access control.

CVE-2024-6884
Gutenberg Blocks with AI by Kadence WP Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-54951
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.

CVE-2024-12768
Responsive iframe Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-29506
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

CVE-2024-53569
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter.

CVE-2024-3630
HL Twitter Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-29833
PhotoGallery General
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An attacker must target an authenticated user with permissions to access this feature, however once uploaded the payload is also accessible to unauthenticated users.

CVE-2024-24115
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2024-8851
Polls CP Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

CVE-2024-8647
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-22 1 PoC

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVE-2024-11108
Serious Slider Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-33724
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
0.3%
2024 0 PoCs

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

CVE-2024-46878
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.