7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43731
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "zone_name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0333
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-26447
OX App Suite Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content. No publicly available exploits are known.

CVE-2023-28908
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-190 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-51281
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters.

CVE-2023-1318
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-1069
Complianz Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-43707
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "CatalogsPageDescriptionForm[1][name] " parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-2334
edd-google-sheet-connector-pro Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-30096
Software Genérico Web
5.4
MEDIUM
EPSS
0.8%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field.

CVE-2023-0406
modoboa/modoboa Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-4811
WordPress File Upload Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

CVE-2023-6030
LogDash Activity Log Web Database Windows ⚡ nuclei
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker

CVE-2023-43711
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "admin_firstname" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-6485
Html5 Video Player Web Windows
5.4
MEDIUM
EPSS
1.9%
2023 1 PoC

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVE-2023-3372
Lana Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0643
squidex/squidex General
5.4
MEDIUM
EPSS
0.4%
2023 CWE-167 1 PoC

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVE-2023-5598
3DSwymer Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allow an attacker to execute arbitrary script code.

CVE-2023-48197
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.

CVE-2023-6127
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.