7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-54795
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.

CVE-2024-4232
Digisol Router DG-GR1321 Networking
5.4
MEDIUM
EPSS
2.0%
2024 CWE-256 4 PoCs

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.

CVE-2024-0719
Tabs Shortcode and Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tabs Shortcode and Widget WordPress plugin through 1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-10151
Auto iFrame Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-1746
Testimonial Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-53975
Firefox for iOS Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.

CVE-2024-5447
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-27703
Software Genérico General
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

CVE-2024-33111
Software Genérico Web Networking
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

CVE-2024-21286
PeopleSoft Enterprise ELM Enterprise Learning Management Web Database
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM Enterprise Learning Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise ELM Enterprise Learning Management, attacks may significantly impact additional products (scop

CVE-2024-3978
WordPress Jitsi Shortcode Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-11671
Remote Desktop Manager Database Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-287 1 PoC

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.

CVE-2024-7008
Calibre Web ⚡ nuclei
5.4
MEDIUM
EPSS
13.4%
2024 CWE-79 1 PoC

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

CVE-2024-51031
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.

CVE-2024-20377
Cisco Firepower Management Center Web Networking
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker could exploit this vulnerability by by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browse

CVE-2024-5595
Essential Blocks Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5074
wp-eMember Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-48569
Software Genérico Web
5.4
MEDIUM
EPSS
3.1%
2024 2 PoCs

Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/

CVE-2024-53568
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.

CVE-2024-45986
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.