7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4771
CKEditor Web
6.1
MEDIUM
EPSS
22.3%
2023 CWE-79 1 PoC

A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.

CVE-2023-6161
WP Crowdfunding Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-3169
tagDiv Composer Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
36.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

CVE-2023-23077
Software Genérico Web
6.1
MEDIUM
EPSS
25.7%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.

CVE-2023-3523
gpac/gpac General
6.1
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-0878
nuxt/framework Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.

CVE-2023-51802
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the page or class_month parameter in the /php-attendance/attendance_report component.

CVE-2023-26149
quill-mention Web
6.1
MEDIUM
EPSS
1.2%
2023 CWE-79 1 PoC

Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:** If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.

CVE-2023-39514
cacti Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `graphs.php` displays graph details such as data-source paths, data template information and graph related fields. _CENSUS_ found that an adversary that is able to configure either a data-source template with m

CVE-2023-0448
WP Helper Lite Wordpress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
27.7%
2023 1 PoC

The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.

CVE-2023-2023
Custom 404 Pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
80.9%
2023 2 PoCs

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2023-0738
OrangeScrum General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.

CVE-2023-0514
Membership Database Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
12.5%
2023 1 PoC

The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6000
Popup Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
69.1%
2023 4 PoCs

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CVE-2023-39218
Zoom Clients General
6.1
MEDIUM
EPSS
0.4%
2023 CWE-602 1 PoC

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-27151
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity Number field.

CVE-2023-4819
Shared Files Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

CVE-2023-33495
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Craft CMS through 4.4.9 is vulnerable to HTML Injection.

CVE-2023-4687
Page Builder: Pagelayer Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.

CVE-2023-1996
3DEXPERIENCE Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) vulnerability in Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x allows an attacker to execute arbitrary script code.