7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5440
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-45614
puma Web
5.4
MEDIUM
EPSS
0.7%
2024 CWE-639 1 PoC

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on proxy set variables is affected. v6.4.3/v5.6.9 now discards any headers using underscores if the non-underscore version also exists. Effectively, allowing the proxy defined headers to always win. Users are advised to upgrade. Nginx has a underscores_in_headers configuration variable to discard these headers at the proxy level as a mitigation. Any

CVE-2024-37764
Software Genérico Web
5.4
MEDIUM
EPSS
7.1%
2024 1 PoC

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

CVE-2024-0561
Ultimate Posts Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-29507
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

CVE-2024-5004
CM Popup Plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-4602
Embed Peertube Playlist Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1849
WP Customer Reviews Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL

CVE-2024-8021
gradio-app/gradio General ⚡ nuclei
5.4
MEDIUM
EPSS
2.4%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.

CVE-2024-9711
EKC Tournament Manager Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-29865
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

CVE-2024-57329
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

CVE-2024-43686
TimeProvider 4100 Web
5.4
MEDIUM
EPSS
14.1%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-2837
WP Chat App Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-46083
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.

CVE-2024-9020
List category posts Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3058
ENL Newsletter Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-9238
AVIF Uploader Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-48312
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.

CVE-2024-45177
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent cross-site scripting (XSS) attacks. It was found out that the camera configuration is vulnerable to a persistent cross-site scripting attack due to insufficient user input validation.