7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-41503
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function.

CVE-2024-28803
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter

CVE-2024-24396
Software Genérico General
6.1
MEDIUM
EPSS
1.8%
2024 2 PoCs

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.

CVE-2024-3867
Tainacan Interface Web Windows
6.1
MEDIUM
EPSS
22.7%
2024 CWE-79 1 PoC

The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-21496
github.com/greenpau/caddy-security Web
6.1
MEDIUM
EPSS
0.1%
2024 CWE-79 2 PoCs

All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header is sanitized by escaping some characters that can allow XSS (e.g., [&], [<], [>], ["], [']), it does not account for the attack based on the JavaScript URL scheme (e.g., javascript:alert(document.domain)// payload). Exploiting this vulnerability may not be trivial, but it could lead to the execution of malicious scripts in the context of the target user’s browser, compromising user sessions.

CVE-2024-7818
Misiek Photo Album Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-5199
Spotify Play Button Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-2387
AFI – The Easiest Integration Plugin Web Database Windows
6.1
MEDIUM
EPSS
44.8%
2024 CWE-89 1 PoC

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries and subsequently inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing

CVE-2024-3590
LetterPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers

CVE-2024-24510
Software Genérico General
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

CVE-2024-12724
WP DeskLite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-20893
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

CVE-2024-13492
Guten Free Options Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2024 1 PoC

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-21034
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-4857
FS Product Inquiry Web Windows
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2024-27443
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
32.4%
2024 0 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

CVE-2024-6018
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-13325
Glossy Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6017
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13669
CalendApp Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.