7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-7045
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVE-2023-21847
Web Applications Desktop Integrator Web Database
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Download). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabili

CVE-2023-49987
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

CVE-2023-0764
Gallery by BestWebSoft Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

CVE-2023-0155
GitLab DevOps
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

CVE-2023-0149
WordPrezi Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WordPrezi WordPress plugin before 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2415
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.4
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.

CVE-2023-0060
Responsive Gallery Grid Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3588
Teamwork Cloud - Business Edition Web Cloud
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.

CVE-2023-26998
Software Genérico General
5.4
MEDIUM
EPSS
0.7%
2023 1 PoC

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

CVE-2023-30788
MonicaHQ General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people/add` endpoint and nickName, description, lastName, middleName and firstName parameter.

CVE-2023-0368
Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2964
Simple Iframe Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.

CVE-2023-29918
Software Genérico General
5.4
MEDIUM
EPSS
5.9%
2023 1 PoC

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

CVE-2023-38687
svelecte Web
5.4
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaScript whenever a Svelecte dropdown is opened. Item names given to Svelecte appear to be directly rendered as HTML by the default item renderer. This means that any HTML tags in the name are rendered as HTML elements not as text. Note that the custom item renderer shown in https://mskocik.github.io/svelecte/#item-rendering is also vulnerable to

CVE-2023-43705
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "translation_value[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-25448
Archivist – Custom Archive Templates Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.

CVE-2023-52059
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.

CVE-2023-43713
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVE-2023-0367
Pricing Tables For WPBakery Page Builder (formerly Visual Composer) Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks