7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-25381
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

CVE-2024-41358
Software Genérico Web
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

CVE-2024-37383
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
64.0%
2024 2 PoCs

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CVE-2024-25551
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.

CVE-2024-57427
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2024 1 PoC

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.

CVE-2024-57033
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

CVE-2024-27744
Software Genérico Web
6.1
MEDIUM
EPSS
4.1%
2024 1 PoC

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.

CVE-2024-3590
LetterPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers

CVE-2024-25411
Software Genérico Web
6.1
MEDIUM
EPSS
19.7%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.

CVE-2024-1550
Firefox General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVE-2024-6076
wp-cart-for-digital-products Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-0973
Widget for Social Page Feeds Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12715
Asgard Security Scanner Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-42341
QueueMetrics General
6.1
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2024-35545
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2024-53470
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

CVE-2024-56918
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form.

CVE-2024-33859
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.

CVE-2024-56115
Software Genérico Web
6.1
MEDIUM
EPSS
1.4%
2024 1 PoC

A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a Cross-Site Scripting (XSS) attack.

CVE-2024-8090
JavaScript Logic Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.