3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-13619
LifterLMS Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12734
Advance Post Prefix Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13331
WP Dream Carousel Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-28734
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
11.3%
2024 1 PoC

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

CVE-2024-13628
WP Pricing Table Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.8%
2024 1 PoC

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-33326
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.0%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.

CVE-2024-13543
Zarinpal Paid Download Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2024 1 PoC

The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12585
Property Hive Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12873
Custom Field Manager Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0250
Analytics Insights for Google Analytics 4 (AIWP) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.2%
2024 1 PoC

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-11044
automatic1111/stable-diffusion-webui General ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-52763
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.6%
2024 0 PoCs

A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter.

CVE-2024-13492
Guten Free Options Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2024 1 PoC

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6892
Journyx (jtime) Web ⚡ nuclei
6.1
MEDIUM
EPSS
7.5%
2024 CWE-81 2 PoCs

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

CVE-2024-13327
Musicbox Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-10812
binary-husky/gpt_academic General ⚡ nuclei
6.1
MEDIUM
EPSS
0.7%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-22927
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
14.0%
2024 0 PoCs

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2024-7313
Shield Security Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
63.9%
2024 2 PoCs

The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13226
A5 Custom Login Page Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-27443
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
32.4%
2024 0 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.