7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0465
Employee Profile Management System Web
3.5
LOW
EPSS
0.1%
2024 CWE-24 1 PoC

A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-250570 is the identifier assigned to this vulnerability.

CVE-2024-1030
eReserv Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in Cogites eReserv 7.7.58. It has been classified as problematic. This affects an unknown part of the file /front/admin/tenancyDetail.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-252303.

CVE-2024-6711
Event Tickets with Ticket Scanner Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks

CVE-2024-0472
Dormitory Management System Web
3.5
LOW
EPSS
0.1%
2024 CWE-200 1 PoC

A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file modifyuser.php. The manipulation of the argument mname leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier VDB-250577 was assigned to this vulnerability.

CVE-2024-13585
Ajax Search Lite Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-0782
Online Railway Reservation System Web
3.5
LOW
EPSS
0.3%
2024 CWE-79 2 PoCs

A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file pass-profile.php. The manipulation of the argument First Name/Last Name/User Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251698 is the identifier assigned to this vulnerability.

CVE-2024-0503
Online FIR System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.

CVE-2024-1922
Online Job Portal Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Employer/ManageJob.php of the component Manage Job Page. The manipulation of the argument Qualification/Description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254857 was assigned to this vulnerability.

CVE-2024-10214
Mattermost General
3.5
LOW
EPSS
0.4%
2024 CWE-303 1 PoC

Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

CVE-2024-10554
WordPress WP-Advanced-Search Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-52759
Software Genérico General
3.5
LOW
EPSS
6.0%
2024 1 PoC

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.

CVE-2024-52754
Software Genérico General
3.5
LOW
EPSS
0.2%
2024 1 PoC

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

CVE-2024-4327
WebViewer General
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unknown part of the component PDF Document Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.9 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-262419. NOTE: The vendor was contacted early about this disclosure and explains that the documentation recomme

CVE-2024-10558
Form Maker by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3996
Smart Post Show Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0504
Simple Online Hotel Reservation System Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file add_reserve.php of the component Make a Reservation Page. The manipulation of the argument Firstname/Lastname with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250618 is the identifier assigned to this vulnerability.

CVE-2024-1215
CRUD without Page Reload Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file fetch_data.php. The manipulation of the argument username/city leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252782 is the identifier assigned to this vulnerability.

CVE-2024-4002
Carousel, Slider, Gallery by WP Carousel Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9771
WP-Recall Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-0284
Food Management System Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as problematic. This issue affects some unknown processing of the file party_submit.php. The manipulation of the argument party_address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249839.