13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-40290
Software Genérico Web Windows
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.

CVE-2023-40000
LiteSpeed Cache Web ⚡ nuclei
8.3
HIGH
EPSS
82.0%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

CVE-2023-2949
openemr/openemr Web ⚡ nuclei
8.3
HIGH
EPSS
71.8%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-5319
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVE-2023-0794
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-1527
tsolucio/corebos Web
8.3
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2023-26153
geokit-rails Web
8.3
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.

CVE-2023-4196
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-45744
Smart Reader Web
8.3
HIGH
EPSS
0.7%
2023 CWE-284 2 PoCs

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to configuration modification. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVE-2023-40287
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-1880
thorsten/phpmyfaq Web ⚡ nuclei
8.3
HIGH
EPSS
14.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-40288
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2024-35219
openapi-generator Web ⚡ nuclei
8.3
HIGH
EPSS
53.2%
2024 CWE-22 0 PoCs

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

CVE-2024-9593
Time Clock Pro Web Windows ⚡ nuclei
8.3
HIGH
EPSS
85.5%
2024 CWE-94 3 PoCs

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.

CVE-2024-41671
twisted Web
8.3
HIGH
EPSS
0.1%
2024 CWE-444 1 PoC

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

CVE-2024-41637
Software Genérico Web
8.3
HIGH
EPSS
0.3%
2024 1 PoC

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.

CVE-2024-41668
cbioportal Web
8.3
HIGH
EPSS
0.1%
2024 CWE-918 1 PoC

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, cBioPortal could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances. A fix has been released in version 6.0.12. As a workaround, one might be able to disable `/proxy` endpoint entirely via, for example, nginx.

CVE-2024-4749
wp-eMember Web Windows
8.3
HIGH
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-5410
IAP-420 Web
8.3
HIGH
EPSS
1.9%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2024-27971
Premmerce Permalink Manager for WooCommerce Web
8.3
HIGH
EPSS
67.4%
2024 CWE-98 1 PoC

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.