13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-5420
utnserver Pro Web ⚡ nuclei
8.3
HIGH
EPSS
46.6%
2024 CWE-79 6 PoCs

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2019-20361
Software Genérico Web Database Windows
8.3
HIGH
EPSS
28.1%
2019 3 PoCs

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

CVE-2019-17094
Belkin WeMo Insight Switch Web
8.3
HIGH
EPSS
0.2%
2019 CWE-121 1 PoC

A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions.

CVE-2021-2218
PeopleSoft Enterprise PT PeopleTools Web Database
8.3
HIGH
EPSS
0.4%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Health Center). Supported versions that are affected are 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools accessible da

CVE-2021-33703
SAP NetWeaver Enterprise Portal (Application Extensions) Web
8.3
HIGH
EPSS
0.7%
2021 CWE-79 1 PoC

Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack results in Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-39155
istio Web
8.3
HIGH
EPSS
0.2%
2021 CWE-178 2 PoCs

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), Istio authorization policy should compare the hostname in the HTTP Host header in a case insensitive way, but currently the comparison is case sensitive. The proxy will route the request hostname in a case-insensitive way which means the authorization policy could be bypassed. As an example, the user may have an authorization policy that rejects re

CVE-2021-2461
Communications Interactive Session Recorder Web Database
8.3
HIGH
EPSS
0.8%
2021 1 PoC

Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications (component: Provision API). The supported version that is affected is 6.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder. While the vulnerability is in Oracle Communications Interactive Session Recorder, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commun

CVE-2021-33702
SAP NetWeaver Enterprise Portal Web
8.3
HIGH
EPSS
0.7%
2021 CWE-79 1 PoC

Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.

CVE-2017-20192
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Web Windows ⚡ nuclei
8.3
HIGH
EPSS
28.7%
2017 CWE-79 1 PoC

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVE-2012-10018
Mapplic Lite Web Windows ⚡ nuclei
8.3
HIGH
EPSS
3.4%
2012 CWE-918 2 PoCs

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

CVE-2025-60954
Software Genérico Web
8.3
HIGH
EPSS
0.1%
2025 1 PoC

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

CVE-2025-3776
Verification SMS with TargetSMS Web Windows
8.3
HIGH
EPSS
0.7%
2025 CWE-94 1 PoC

The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().

CVE-2025-26529
moodle Web
8.3
HIGH
EPSS
1.0%
2025 CWE-79 1 PoC

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

CVE-2025-34066
IP cameras Web Cloud
8.3
HIGH
EPSS
0.2%
2025 CWE-295 2 PoCs

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.

CVE-2025-4759
lockfile-lint-api Web
8.3
HIGH
EPSS
0.2%
2025 CWE-179 1 PoC

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.

CVE-2025-54075
mdc Web
8.3
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context. Version 0.17.2 contains a fix for the issue.

CVE-2025-42620
Vulnerability-Lookup Web
8.3
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

In affected versions, vulnerability-lookup handled user-controlled content in comments and bundles in an unsafe way, which could lead to stored Cross-Site Scripting (XSS). On the backend, the related_vulnerabilities field of bundles accepted arbitrary strings without format validation or proper sanitization. On the frontend, comment and bundle descriptions were converted from Markdown to HTML and then injected directly into the DOM using string templates and innerHTML. This combination allowed an attacker who could create or edit comments or bundles to store crafted HTML/JavaScript

CVE-2025-60880
Software Genérico Web
8.3
HIGH
EPSS
0.0%
2025 1 PoC

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.

CVE-2020-36730
CMP – Coming Soon & Maintenance Plugin by NiteoThemes Web Windows
8.3
HIGH
EPSS
46.4%
2020 CWE-862 2 PoCs

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

CVE-2020-35785
Software Genérico Web
8.3
HIGH
EPSS
0.1%
2020 1 PoC

NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).