13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-15889
Software Genérico Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
5.0%
2019 5 PoCs

The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

CVE-2019-25225
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVE-2019-14862
knockout Web
6.1
MEDIUM
EPSS
0.2%
2019 CWE-79 5 PoCs

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVE-2019-4645
Cognos Analytics Web
6.1
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170881.

CVE-2019-1642
Cisco Firepower Management Center Web Networking
6.1
MEDIUM
EPSS
0.9%
2019 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script

CVE-2019-4632
Security Secret Server Web
6.1
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170004.

CVE-2019-19089
eSOMS Web
6.1
MEDIUM
EPSS
0.4%
2019 CWE-16 1 PoC

For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.

CVE-2019-14881
moodle Web
6.1
MEDIUM
EPSS
0.5%
2019 CWE-79 1 PoC

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVE-2021-25022
UpdraftPlus WordPress Backup Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

CVE-2021-43062
Fortinet FortiMail Web Networking ⚡ nuclei
6.1
MEDIUM
EPSS
57.1%
2021 1 PoC

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

CVE-2021-2142
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). The supported version that is affected is 10.3.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle

CVE-2021-31851
McAfee Policy Auditor Web
6.1
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extraction of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.

CVE-2021-4050
livehelperchat/livehelperchat Web
6.1
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-2040
Argus Safety Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Case Form, Local Affiliate Form). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Argus Safety. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Argus Safety, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete acc

CVE-2021-28957
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2021 1 PoC

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

CVE-2021-25959
opencrx-core-config Web
6.1
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.

CVE-2021-23398
react-bootstrap-table Web
6.1
MEDIUM
EPSS
0.4%
2021 2 PoCs

All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.

CVE-2021-35665
Hyperion Financial Reporting Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperion Financial Reporting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some

CVE-2021-39350
FV Flowplayer Video Player Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.6%
2021 CWE-79 0 PoCs

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

CVE-2021-25969
camaleon_cms Web
6.1
MEDIUM
EPSS
1.5%
2021 CWE-79 1 PoC

In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.