7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-39836
Mattermost General
4.8
MEDIUM
EPSS
0.5%
2024 CWE-693 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.

CVE-2024-11097
Student Record Management System General
4.8
MEDIUM
EPSS
0.0%
2024 CWE-835 1 PoC

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main Menu. The manipulation leads to infinite loop. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVE-2024-13482
Icegram Engage Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12739
Mobile Contact Bar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12354
Phone Contact Manager System General
4.8
MEDIUM
EPSS
0.2%
2024 CWE-120 2 PoCs

A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVE-2024-11843
Panorama Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-1958
wpb-show-core Web Windows
4.8
MEDIUM
EPSS
1.1%
2024 1 PoC

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

CVE-2024-13616
VikBooking Hotel Booking Engine & PMS Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-45964
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

CVE-2024-6889
Secure Copy Content Protection and Content Locking Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7132
Page Builder Gutenberg Blocks Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13382
Calculated Fields Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-21492
github.com/greenpau/caddy-security General
4.8
MEDIUM
EPSS
1.1%
2024 CWE-613 1 PoC

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.

CVE-2024-9182
Maspik Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-7556
Simple Share Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6393
Photo Gallery, Sliders, Proofing and Themes Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7879
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-7759
PWA for WP Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-22720
Software Genérico General
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.

CVE-2024-5578
Table of Contents Plus Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed