7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-32681
requests Web
6.1
MEDIUM
EPSS
6.1%
2023 CWE-200 1 PoC

Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel, the proxy will identify the header in the request itself and remove it prior to forwarding to the destination server. However when sent over HTTPS, the `Proxy-Authorization` header must be sent in the CONNECT request as the proxy has no visibility into the tunneled request. This r

CVE-2023-30148
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and /sourcefiles/blockhtml.php.

CVE-2023-48858
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via the login.php? URL part.

CVE-2023-1835
Ninja Forms Contact Form Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2023 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-39512
cacti Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_sources.php` displays the data source management information (e.g. data source path, polling configuration, device name related to the datasource etc.) for different data visualizations of the _cacti_ app

CVE-2023-49088
cacti Web
6.1
MEDIUM
EPSS
1.0%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious data source path in `data_debug.php`. To perform the cross-site scripting attack, the adversary needs to be an authorized cacti user with the following permissions: `General Administration>Sites/Devices/Data`. The victim of this attack could be any account with permissions to view `http://<HOST>/cacti/data_debug.php`. As

CVE-2023-0442
Loan Comparison Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

CVE-2023-1805
Product Catalog Feed by PixelYourSite Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-5951
Welcart e-Commerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1373
W4 Post List Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-4451
cockpit-hq/cockpit Web ⚡ nuclei
6.1
MEDIUM
EPSS
63.6%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-6541
Allow SVG Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-2340
pimcore/pimcore Web
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-4771
CKEditor Web
6.1
MEDIUM
EPSS
22.3%
2023 CWE-79 1 PoC

A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.

CVE-2023-44012
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
15.2%
2023 0 PoCs

Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.

CVE-2023-46951
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

CVE-2023-39366
cacti Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The `data_sources.php` script displays the data source management information (e.g. data source path, polling configuration etc.) for different data visualizations of the _cacti_ app. CENSUS found that an adversary that is able to c

CVE-2023-23491
Quick Event Manager WordPress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
11.1%
2023 1 PoC

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

CVE-2023-49973
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.

CVE-2023-23128
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.