13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-46369
FTP server Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields.

CVE-2022-0954
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
4.3%
2022 CWE-79 1 PoC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-2495
microweber/microweber Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2022-4764
Simple File Downloader Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4471
YARPP Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4682
Lightbox Gallery Web Windows
6.8
MEDIUM
EPSS
0.8%
2022 1 PoC

The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-0145
forkcms/forkcms Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.

CVE-2022-38451
FreshTomato Web
6.8
MEDIUM
EPSS
4.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-4759
GigPress Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-36325
RUGGEDCOM RM1224 LTE(4G) EU Web
6.8
MEDIUM
EPSS
0.4%
2022 CWE-80 1 PoC

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

CVE-2022-0928
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
6.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-4488
Widgets on Pages Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2026-5944
Cisco Intersight Device Connector for Prism Central Web Networking
6.7
MEDIUM
EPSS
0.1%
2026 CWE-306 1 PoC

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network access can exploit this vulnerability by sending crafted requests to the exposed endpoint to enumerate cluster metadata, including virtual machine information and cluster config

CVE-2023-24518
Pandora FMS Web
6.7
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.

CVE-2023-0828
Pandora FMS Web
6.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2019-3887
Kernel Web
6.7
MEDIUM
EPSS
0.0%
2019 CWE-863 1 PoC

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

CVE-2021-2151
PeopleSoft Enterprise PT PeopleTools Web Database
6.7
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and

CVE-2021-3812
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-3811
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-23814
unisharp/laravel-filemanager Web
6.7
MEDIUM
EPSS
2.1%
2021 CWE-94 3 PoCs

This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an image file, then capture the request 4. Edit the request contents with a malicious file (webshell) 5. Enter the path of file uploaded on URL - Remote Code Execution **Note:** Prevention for bad extensions can be done by using a whitelist in the config file(lfm.php). Correspon