6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9283
ReLaXed General
4.8
MEDIUM
EPSS
0.0%
2024 CWE-79 1 PoC

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVE-2024-9428
Popup Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-56463
QRadar SIEM Web
4.8
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2024-10893
WP Booking Calendar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12566
Email Subscribers by Icegram Express Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5002
User Submitted Posts Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13384
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8670
Photo Gallery by 10Web Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3899
Gallery Plugin for WordPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.

CVE-2024-53617
Software Genérico General
4.8
MEDIUM
EPSS
5.3%
2024 1 PoC

A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.

CVE-2024-5172
Expert Invoice Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1401
Profile Box Shortcode And Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Profile Box Shortcode And Widget WordPress plugin before 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10939
Image Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-57514
Software Genérico Web Networking ⚡ nuclei
4.8
MEDIUM
EPSS
7.8%
2024 2 PoCs

The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.

CVE-2024-9882
Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8702
Backup Database Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8619
Ajax Search Lite Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9768
Formidable Forms Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13544
Zarinpal Paid Download Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2024-48948
Software Genérico General
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.