7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-26454
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.

CVE-2024-24097
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

CVE-2024-6408
Slider by 10Web Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2404
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.

CVE-2024-7353
Accept Stripe Payments Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-46494
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

CVE-2024-57429
Software Genérico Web
5.4
MEDIUM
EPSS
0.9%
2024 1 PoC

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

CVE-2024-48170
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.

CVE-2024-7690
DN Popup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-42335
7Twenty Bot Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-21064
Business Intelligence Enterprise Edition Web Database
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Succes

CVE-2024-46879
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.

CVE-2024-8397
webtoffee-gdpr-cookie-consent Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

CVE-2024-20047
MT6739, MT6768, MT6781, MT6833, MT6853, MT6877, MT6883, MT6885, MT6893, MT8183, MT8188, MT8765, MT8766, MT8768, MT8786, MT8788, MT8791, MT8797 General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587865; Issue ID: ALPS08486807.

CVE-2024-9709
EKC Tournament Manager Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-2402
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-21510
sinatra Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-807 1 PoC

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVE-2024-30464
Social Icons Widget & Block by WPZOOM General ⚡ nuclei
5.4
MEDIUM
EPSS
43.5%
2024 CWE-862 0 PoCs

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

CVE-2024-37799
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

CVE-2024-21264
PeopleSoft Enterprise CC Common Application Objects Web Database
5.4
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized read access to a subset of PeopleSoft Enterpr