13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-59712
Snipe-IT Web
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Snipe-IT before 8.1.18 allows XSS.

CVE-2025-11241
Yoast SEO Premium Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-80 1 PoC

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.

CVE-2025-50071
Oracle Applications Framework Web Database
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data

CVE-2020-6120
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The fn parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27231
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-23831
Software Genérico Web
6.4
MEDIUM
EPSS
0.5%
2020 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and session cookies when an unauthenticated victim clicks on a malicious URL and enters credentials.

CVE-2020-6134
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page MassDropModal.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-13526
ProcessMaker Web Database
6.4
MEDIUM
EPSS
1.6%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27236
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27241
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6131
OS4ED Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassScheduleSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27226
OpenClinic Web Database
6.4
MEDIUM
EPSS
1.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6145
ERPNext Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6136
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6125
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-4757
Content Navigator Web
6.4
MEDIUM
EPSS
0.4%
2020 2 PoCs

IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188600.

CVE-2020-6130
OS4ED Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassDropSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27242
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-4863
Rational Quality Manager Web
6.4
MEDIUM
EPSS
0.2%
2020 1 PoC

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.

CVE-2020-27245
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.