7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0442
Loan Comparison Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

CVE-2023-33986
SAP CRM ABAP (Grantor Management) Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.

CVE-2023-5211
Fattura24 Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting vulnerability.

CVE-2023-1420
Ajax Search Lite Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-27293
OpenCATS Web
6.1
MEDIUM
EPSS
3.0%
2023 1 PoC

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

CVE-2023-31020
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
6.1
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.

CVE-2023-5631
🔥 KEV Roundcubemail Web
6.1
MEDIUM
EPSS
84.4%
2023 CWE-79 2 PoCs

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVE-2023-40819
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

CVE-2023-1080
GN Publisher: Google News Compatible RSS Feeds Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
44.7%
2023 CWE-79 0 PoCs

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-4250
EventPrime Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-2407
Event Registration Calendar By vcita Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-23128
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.

CVE-2023-3041
Autochat Automatic Conversation Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

CVE-2023-27572
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter.

CVE-2023-27499
GUI for HTML Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.

CVE-2023-27666
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Auto Dealer Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the name parameter at /classes/SystemSettings.php?f=update_settings.

CVE-2023-1877
microweber/microweber General
6.1
MEDIUM
EPSS
4.7%
2023 CWE-77 1 PoC

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-37580
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
93.9%
2023 0 PoCs

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

CVE-2023-30256
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
70.3%
2023 2 PoCs

Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

CVE-2023-6956
EasyAzon – Amazon Associates Affiliate Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2023 CWE-79 1 PoC

The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘easyazon-cloaking-locale’ parameter in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.