7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2609
Firefox General
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVE-2024-29029
memos Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.9%
2024 CWE-918 0 PoCs

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.

CVE-2024-8095
BabelZ Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-21072
Installed Base Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Data Provider UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Installed Base, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delet

CVE-2024-31586
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.

CVE-2024-11503
WP Tabs Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4616
Widget Bundle Web Windows
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users

CVE-2024-3580
Popup4Phone Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-55059
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.

CVE-2024-57423
Software Genérico Web Cloud
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.

CVE-2024-13222
User Messages Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.6%
2024 1 PoC

The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0238
EventON Premium Web Windows
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVE-2024-45176
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting (XSS) attacks. It was found out that different functions are prone to reflected cross-site scripting attacks due to insufficient user input validation.

CVE-2024-0233
EventON Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5811
Simple Video Directory Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4924
Social Sharing Plugin Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6272
SpiderContacts Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-3590
LetterPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers

CVE-2024-24136
Software Genérico Web
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

CVE-2024-25435
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.