7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28435
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

CVE-2024-36441
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.

CVE-2024-55232
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.

CVE-2024-4860
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.

CVE-2024-29810
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-46077
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

CVE-2024-1142
IQ Server General
5.4
MEDIUM
EPSS
0.3%
2024 CWE-22 1 PoC

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.

CVE-2024-7846
YITH WooCommerce Ajax Search Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

CVE-2024-5713
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-28784
QRadar SIEM Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893.

CVE-2024-10637
Gutenberg Blocks with AI by Kadence WP Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5644
Tournamatch Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-37396
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.

CVE-2024-53408
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2024-48119
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

CVE-2024-25434
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.

CVE-2024-10892
Cost Calculator Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-4270
SVGMagic Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-56377
REDCap Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (which has been injected into all survey fields) is executed, potentially enabling the execution of arbitrary web scripts.

CVE-2024-41447
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.