7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1274
My Calendar Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)

CVE-2024-10818
JSFiddle Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-39031
Software Genérico Web
5.4
MEDIUM
EPSS
6.7%
2024 1 PoC

In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event.

CVE-2024-4005
Social Pixel Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9879
Melapress File Monitor Web Database Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-38430
Tafnit v8 Web
5.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-13667
Uncode Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-13101
WP MediaTagger Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3846
Chrome General
5.4
MEDIUM
EPSS
1.2%
2024 2 PoCs

Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-27665
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.

CVE-2024-7691
Flaming Forms Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.

CVE-2024-46409
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.

CVE-2024-24397
Software Genérico General
5.4
MEDIUM
EPSS
1.2%
2024 2 PoCs

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

CVE-2024-42758
Software Genérico Web
5.4
MEDIUM
EPSS
1.9%
2024 1 PoC

A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A malicious attacker can input XSS payloads for example when creating or editing existing page, to trigger the XSS on Dokuwiki, which is then stored in .txt file (due to nature of how Dokuwiki is designed), which presents stored XSS.

CVE-2024-24099
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

CVE-2024-37673
Software Genérico General
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.

CVE-2024-10637
Gutenberg Blocks with AI by Kadence WP Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-11841
Tithe.ly Giving Button Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5728
Animated AL List Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-54772
Software Genérico Networking
5.4
MEDIUM
EPSS
2.0%
2024 2 PoCs

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.