7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6627
WP Go Maps (formerly WP Google Maps) Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 2 PoCs

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.

CVE-2023-3292
grid-kit-premium Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-22432
web2py General ⚡ nuclei
6.1
MEDIUM
EPSS
40.8%
2023 1 PoC

Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

CVE-2023-26146
ithewei/libhv Web
6.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.

CVE-2023-42308
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" and "Subject Code" Section.

CVE-2023-6050
Estatik Real Estate Plugin Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-33985
SAP NetWeaver Enterprise Portal Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2023-46448
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.

CVE-2023-32218
IX Workforce Engagement General
6.1
MEDIUM
EPSS
0.1%
2023 CWE-601 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2023-0876
WP Meta SEO Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

CVE-2023-6389
WordPress Toolbar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
52.5%
2023 1 PoC

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2023-3169
tagDiv Composer Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
36.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

CVE-2023-2743
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-1119
WP-Optimize Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
24.2%
2023 1 PoC

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.

CVE-2023-23078
Software Genérico Web
6.1
MEDIUM
EPSS
26.2%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

CVE-2023-21482
Samsung Camera General
6.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.

CVE-2023-3992
PostX Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-29623
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
27.4%
2023 1 PoC

Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

CVE-2023-24192
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.

CVE-2023-23075
Software Genérico Web
6.1
MEDIUM
EPSS
6.8%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.