7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2470
Simple Ajax Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-36837
Software Genérico Web Database ⚡ nuclei
5.4
MEDIUM
EPSS
91.7%
2024 2 PoCs

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

CVE-2024-51026
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

CVE-2024-3978
WordPress Jitsi Shortcode Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3241
Ultimate Blocks Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-53543
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.

CVE-2024-8536
Ultimate Blocks Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5627
Tournamatch Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.

CVE-2024-1658
Grid Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-28593
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVE-2024-39929
Software Genérico General
5.4
MEDIUM
EPSS
60.3%
2024 2 PoCs

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVE-2024-6884
Gutenberg Blocks with AI by Kadence WP Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-55570
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to increase their privileges by sending a single HTTP PUT request with rolename=Administrator, aka incorrect access control.

CVE-2024-6710
Ditty Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2024-53975
Firefox for iOS Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.

CVE-2024-1746
Testimonial Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0820
Jobs for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-54997
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

CVE-2024-10482
Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-13099
Widget4Call Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
4.3%
2024 1 PoC

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.