7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-4900
SEOPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

CVE-2024-55040
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.

CVE-2024-36395
WFO Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-80 1 PoC

Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVE-2024-9651
Fluent Forms Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-33893
Software Genérico Web Cloud
6.1
MEDIUM
EPSS
1.6%
2024 2 PoCs

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.

CVE-2024-23995
Software Genérico DevOps Web
6.1
MEDIUM
EPSS
1.5%
2024 2 PoCs

Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.

CVE-2024-23055
Software Genérico DevOps ⚡ nuclei
6.1
MEDIUM
EPSS
4.0%
2024 1 PoC

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

CVE-2024-37888
ckeditor-plugin-openlink Web
6.1
MEDIUM
EPSS
20.6%
2024 CWE-79 1 PoC

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.

CVE-2024-37383
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
64.0%
2024 2 PoCs

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CVE-2024-40817
Safari General
6.1
MEDIUM
EPSS
0.4%
2024 3 PoCs

The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.

CVE-2024-25551
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.

CVE-2024-4384
CSSable Countdown Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-27744
Software Genérico Web
6.1
MEDIUM
EPSS
4.1%
2024 1 PoC

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.

CVE-2024-25411
Software Genérico Web
6.1
MEDIUM
EPSS
19.7%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.

CVE-2024-2278
Themify Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1550
Firefox General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVE-2024-21202
PeopleSoft Enterprise PeopleTools Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result i

CVE-2024-6076
wp-cart-for-digital-products Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-54792
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.

CVE-2024-0973
Widget for Social Page Feeds Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)