7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-24397
Software Genérico General
5.4
MEDIUM
EPSS
1.2%
2024 2 PoCs

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

CVE-2024-5249
Akana API Platform Web
5.4
MEDIUM
EPSS
0.3%
2024 CWE-294 1 PoC

In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

CVE-2024-34471
Software Genérico Web
5.4
MEDIUM
EPSS
1.7%
2024 1 PoC

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.

CVE-2024-1846
Responsive Tabs Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-9160
PEADM Forge Module General
5.4
MEDIUM
EPSS
0.0%
2024 CWE-295 1 PoC

In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.

CVE-2024-31649
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.

CVE-2024-4483
Email Encoder Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

CVE-2024-27593
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-54998
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

CVE-2024-45177
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent cross-site scripting (XSS) attacks. It was found out that the camera configuration is vulnerable to a persistent cross-site scripting attack due to insufficient user input validation.

CVE-2024-46209
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.

CVE-2024-10146
Simple File List Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2024 1 PoC

The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.

CVE-2024-9645
Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-37394
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.

CVE-2024-6074
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-11502
Planning Center Online Giving Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-53976
Firefox for iOS General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.

CVE-2024-20829
Samsung Internet General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

CVE-2024-42406
Mattermost General
5.4
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.