7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2004
curl Web
3.5
LOW
EPSS
0.8%
2024 3 PoCs

When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has

CVE-2024-58248
nopCommerce General
3.5
LOW
EPSS
0.1%
2024 CWE-362 1 PoC

nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.

CVE-2024-2068
Computer Inventory System Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/update-computer.php. The manipulation of the argument model leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255383.

CVE-2024-7083
Email Encoder Web Windows
3.5
LOW
EPSS
0.0%
2024 1 PoC

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13124
Photo Gallery by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5250
Akana API Platform Web
3.5
LOW
EPSS
0.5%
2024 CWE-209 1 PoC

In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

CVE-2024-13125
Everest Forms Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4004
Advanced Cron Manager Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1103
Real Estate Management System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 2 PoCs

A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x onerror=alert(document.cookie)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252458 is the identifier assigned to this vulnerability.

CVE-2024-10710
YaDisk Files Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-0599
Jspxcms Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java of the component Document Management Page. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250837 was assigned to this vulnerability.

CVE-2024-55416
Software Genérico Web ⚡ nuclei
3.5
LOW
EPSS
1.4%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

CVE-2024-51337
Software Genérico Web
3.5
LOW
EPSS
0.3%
2024 1 PoC

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/user_manage_editProcess.php.

CVE-2024-0958
Stock Management System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252203.

CVE-2024-3529
Complete Online Student Management System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in Campcodes Complete Online Student Management System 1.0. It has been classified as problematic. This affects an unknown part of the file students_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259899.

CVE-2024-12769
Simple Banner Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-1267
Restaurant POS System Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-253010 is the identifier assigned to this vulnerability.

CVE-2024-10560
Form Maker by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-21242
Oracle Database Server Web Database
3.5
LOW
EPSS
0.1%
2024 1 PoC

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVS

CVE-2024-1028
Facebook News Feed Like General
3.5
LOW
EPSS
0.0%
2024 CWE-79 1 PoC

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Post Handler. The manipulation of the argument Description with the input <marquee>HACKED</marquee> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252301 was assigned to this vulnerability.