7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-37856
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.

CVE-2024-55057
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

CVE-2024-2583
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.

CVE-2024-48246
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.

CVE-2024-4094
Simple Share Buttons Adder Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-40473
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.

CVE-2024-10980
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-9662
CYAN Backup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9838
Auto Affiliate Links Web Database Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-3752
Crelly Slider Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-46082
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

CVE-2024-56376
REDCap Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.

CVE-2024-29507
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

CVE-2024-10460
Firefox General
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVE-2024-45614
puma Web
5.4
MEDIUM
EPSS
0.7%
2024 CWE-639 1 PoC

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on proxy set variables is affected. v6.4.3/v5.6.9 now discards any headers using underscores if the non-underscore version also exists. Effectively, allowing the proxy defined headers to always win. Users are advised to upgrade. Nginx has a underscores_in_headers configuration variable to discard these headers at the proxy level as a mitigation. Any

CVE-2024-3978
WordPress Jitsi Shortcode Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-0561
Ultimate Posts Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4602
Embed Peertube Playlist Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1849
WP Customer Reviews Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL

CVE-2024-8021
gradio-app/gradio General ⚡ nuclei
5.4
MEDIUM
EPSS
2.4%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.