13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0352
janeczku/calibre-web Web
8.5
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.

CVE-2022-50930
Emerson PAC Machine Edition Web
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2022-50789
Impact/Pulse/First Web
8.5
HIGH
EPSS
1.6%
2022 CWE-78 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vulnerable dns.php script, which triggers command execution and then deletes the file.

CVE-2022-50791
Impact/Pulse/First Web
8.5
HIGH
EPSS
4.8%
2022 CWE-78 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, which triggers the malicious file and then deletes it.

CVE-2023-5060
librenms/librenms Web
8.4
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

CVE-2023-41791
Pandora FMS Web
8.4
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed users with low privileges to introduce Javascript executables via a translation string that could affect the integrity of some configuration files. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-45303
Software Genérico Web
8.4
HIGH
EPSS
0.8%
2023 1 PoC

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

CVE-2023-46672
Logstash Web
8.4
HIGH
EPSS
0.2%
2023 CWE-532 2 PoCs

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue are: * Logstash is configured to log in JSON format https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html , which is not the default logging format. * Sensitive data is stored in the Logstash keystore and referenced as a variable in Logstash configuration.

CVE-2023-2533
🔥 KEV PaperCut NG/MF Web
8.4
HIGH
EPSS
36.3%
2023 CWE-352 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.

CVE-2023-1755
thorsten/phpmyfaq Web
8.4
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-47129
cms Web
8.4
HIGH
EPSS
5.4%
2023 CWE-434 1 PoC

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.

CVE-2024-51379
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.

CVE-2024-51380
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.

CVE-2024-27169
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
8.4
HIGH
EPSS
0.0%
2024 CWE-306 1 PoC

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/models/versions, see the reference URL.

CVE-2024-28143
Scan2Net Web
8.4
HIGH
EPSS
0.1%
2024 CWE-620 2 PoCs

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.

CVE-2024-25858
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.

CVE-2024-46278
Software Genérico Web
8.4
HIGH
EPSS
1.2%
2024 1 PoC

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

CVE-2024-51382
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compromise the integrity and security of the system.

CVE-2024-51381
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

CVE-2019-16641
Software Genérico Web
8.4
HIGH
EPSS
0.0%
2019 1 PoC

An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1.