6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6073
wp-cart-for-digital-products Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-33299
Software Genérico General
4.7
MEDIUM
EPSS
1.1%
2024 1 PoC

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users

CVE-2024-2159
Social Sharing Plugin Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5575
Ditty Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-24050
Software Genérico Web
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.

CVE-2024-2497
raspap-webgui Web
4.7
MEDIUM
EPSS
0.1%
2024 CWE-94 1 PoC

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-45984
Software Genérico Web
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject malicious scripts that will be executed when the Donor List is viewed.

CVE-2024-0931
AC10U General
4.7
MEDIUM
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4501
RG-UAC Web
4.7
MEDIUM
EPSS
0.3%
2024 CWE-78 1 PoC

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file /view/bugSolve/captureData/commit.php. The manipulation of the argument tcpDump leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263105 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5727
Widget4Call Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-1819
Membership Management System General
4.7
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add Members Tab. The manipulation of the argument Member Photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254607.

CVE-2024-1008
Employee Management System Web
4.7
MEDIUM
EPSS
0.1%
2024 CWE-434 2 PoCs

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Profile Page. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252277 was assigned to this vulnerability.

CVE-2024-1754
NPS computy Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-54910
Software Genérico General
4.7
MEDIUM
EPSS
1.2%
2024 1 PoC

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

CVE-2024-36494
Scan2Net Web
4.7
MEDIUM
EPSS
0.2%
2024 CWE-79 2 PoCs

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

CVE-2024-4217
shortcodes-ultimate-pro Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

CVE-2024-30052
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) General
4.7
MEDIUM
EPSS
1.8%
2024 CWE-693 1 PoC

Visual Studio Remote Code Execution Vulnerability

CVE-2024-33297
Software Genérico General
4.7
MEDIUM
EPSS
1.0%
2024 1 PoC

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function

CVE-2024-50585
License Server Administration System Web
4.7
MEDIUM
EPSS
0.4%
2024 CWE-79 2 PoCs

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request.  The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor a

CVE-2024-1292
wpb-show-core Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin