13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4329
Product list Widget for Woocommerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).

CVE-2022-4745
WP Customer Area Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

CVE-2022-46957
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Sourcecodester.com Online Graduate Tracer System V 1.0.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-42343
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

CVE-2023-42345
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

CVE-2026-8656
jsondiffpatch Web
6.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacker-controlled HTML can be interpreted by the browser, resulting in XSS.

CVE-2025-52204
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter

CVE-2022-38481
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

An issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP2. The application is prone to reflected Cross-site Scripting (XSS) in several features.

CVE-2025-15345
MapGeo – Interactive Geo Maps Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 CWE-80 1 PoC

The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2021-45721
JFrog Artifactory Web
6.1
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.

CVE-2025-70890
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affected page is accessed.

CVE-2023-1243
answerdev/answer Web
6.0
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-1239
answerdev/answer Web
6.0
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-21908
Banking Virtual Account Management Web Database
6.0
MEDIUM
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Acco

CVE-2023-2998
thorsten/phpmyfaq Web
6.0
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.

CVE-2023-21907
Banking Virtual Account Management Web Database
6.0
MEDIUM
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Acco

CVE-2023-3822
pimcore/pimcore Web
6.0
MEDIUM
EPSS
10.9%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2024-5921
GlobalProtect App Web Networking
6.0
MEDIUM
EPSS
0.4%
2024 CWE-295 2 PoCs

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

CVE-2024-24898
kernel Web
6.0
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from 4.19.90-2109.1.0.0108 before 4.19.90-2403.4.0.0244.

CVE-2024-23634
geoserver Web
6.0
MEDIUM
EPSS
1.1%
2024 CWE-20 1 PoC

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists in versions prior to 2.23.5 and 2.24.2 that enables an authenticated administrator with permissions to modify stores through the REST Coverage Store or Data Store API to rename arbitrary files and directories with a name that does not end in `.zip`. Store file uploads rename zip files to have a `.zip` extension if it doesn't already have one before unzipping the file. This is fine for file and url upload methods where the files will b