13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-27160
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.1%
2024 CWE-798 2 PoCs

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-40541
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build.

CVE-2024-40540
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept.

CVE-2021-32821
mootools-core Web
6.2
MEDIUM
EPSS
0.2%
2021 CWE-400 1 PoC

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

CVE-2021-21290
netty Web
6.2
MEDIUM
EPSS
0.0%
2021 CWE-378 4 PoCs

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set

CVE-2020-5296
october Web
6.2
MEDIUM
EPSS
0.6%
2020 CWE-73 2 PoCs

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).

CVE-2007-4465
Software Genérico Web
6.1
MEDIUM
EPSS
2.9%
2007 2 PoCs

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

CVE-2007-5817
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2007 1 PoC

dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup, (3) res, or (4) ren action. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) and possibly other attacks.

CVE-2014-3146
Software Genérico Web
6.1
MEDIUM
EPSS
4.3%
2014 2 PoCs

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

CVE-2014-125128
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2014 CWE-79 1 PoC

'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings.

CVE-2026-3884
spin.js Web
6.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser.

CVE-2026-3455
mailparser Web
6.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded malicious JavaScript code.

CVE-2026-30082
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2026 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.

CVE-2026-0618
PowerShell Universal Web
6.1
MEDIUM
EPSS
0.1%
2026 CWE-79 1 PoC

Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.

CVE-2026-29971
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2026 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. User-controlled input is reflected into HTML and JavaScript contexts without proper output encoding, allowing arbitrary JavaScript execution in the victim's browser via the ftpBackup functionality, authentication input handling, search functionality, and error message rendering components

CVE-2026-27645
changedetection.io Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.7%
2026 CWE-79 0 PoCs

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML escaping. Since Flask returns text/html by default for plain string responses, the browser parses and executes injected JavaScript. Version 0.54.1 contains a fix for the issue.

CVE-2026-0561
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Web Windows
6.1
MEDIUM
EPSS
0.1%
2026 CWE-79 1 PoC

The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2026-0858
net.sourceforge.plantuml:plantuml Web
6.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.

CVE-2026-30695
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2026 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The vulnerability is caused by improper sanitization of user-supplied input in the dirBrowse parameter of the /file_manager.cgi endpoint.

CVE-2026-30661
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2026 1 PoC

iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.