13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2026-21631
Joomla! CMS Web
5.9
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Lack of output escaping leads to a XSS vector in the multilingual associations component.

CVE-2026-1867
Guest posting / Frontend Posting / Front Editor Web Windows
5.9
MEDIUM
EPSS
0.1%
2026 1 PoC

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6's settings, it is possible for an unauthenticated attacker to export and download all of the form data/settings, including the administrator's email address.

CVE-2026-3638
Server Web
5.9
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests.

CVE-2023-4653
instantsoft/icms2 Web
5.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-21924
Health Sciences InForm Web Database
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can

CVE-2023-43804
urllib3 Web
5.9
MEDIUM
EPSS
0.9%
2023 CWE-200 2 PoCs

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.

CVE-2023-47184
Admin Bar & Dashboard Access Control Web
5.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.

CVE-2023-30876
Dave's WordPress Live Search Web Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1 versions.

CVE-2023-24516
Pandora FMS Web
5.9
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-21967
Java SE JDK and JRE Web Database
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Ora

CVE-2023-41792
Pandora FMS Web
5.9
MEDIUM
EPSS
0.0%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the SNMP Trap Editor. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-27624
Redirect After Login Web ⚡ nuclei
5.9
MEDIUM
EPSS
0.7%
2023 CWE-79 0 PoCs

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions.

CVE-2023-3782
Software Genérico Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-400 1 PoC

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response

CVE-2023-1212
phpipam/phpipam Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.

CVE-2023-48795
Software Genérico Web Networking
5.9
MEDIUM
EPSS
50.7%
2023 11 PoCs

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack agai

CVE-2024-5764
Nexus Repository Web
5.9
MEDIUM
EPSS
2.6%
2024 CWE-798 2 PoCs

Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated. This issue affects Nexus Repository: from 3.0.0 through 3.72.0.

CVE-2024-8652
NetCat CMS Web
5.9
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.

CVE-2024-41738
TXSeries for Multiplatforms Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-598 1 PoC

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

CVE-2024-27142
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-776 1 PoC

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.

CVE-2024-50624
Software Genérico Web
5.9
MEDIUM
EPSS
0.0%
2024 2 PoCs

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.