578 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-37656
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2024 0 PoCs

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php.

CVE-2024-28734
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
11.3%
2024 1 PoC

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

CVE-2024-13628
WP Pricing Table Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.8%
2024 1 PoC

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-33326
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.0%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.

CVE-2024-6289
WPS Hide Login Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
7.3%
2024 1 PoC

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

CVE-2024-13543
Zarinpal Paid Download Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2024 1 PoC

The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12585
Property Hive Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12873
Custom Field Manager Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0250
Analytics Insights for Google Analytics 4 (AIWP) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.2%
2024 1 PoC

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-12737
WP BASE Booking of Appointments, Services and Events Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13220
WordPress Google Map Professional (Map In Your Language) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-11044
automatic1111/stable-diffusion-webui General ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-13328
Giga Messenger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13225
ECT Home Page Products Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-52762
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.6%
2024 0 PoCs

A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.

CVE-2024-13853
SEO Tools Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.9%
2024 1 PoC

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-52763
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.6%
2024 0 PoCs

A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter.

CVE-2024-13492
Guten Free Options Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2024 1 PoC

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-8883
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.6%
2024 CWE-601 2 PoCs

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

CVE-2024-6892
Journyx (jtime) Web ⚡ nuclei
6.1
MEDIUM
EPSS
7.5%
2024 CWE-81 2 PoCs

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.