13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2018-11075
Authentication Manager Web
5.8
MEDIUM
EPSS
0.8%
2018 1 PoC

RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security Console page. A remote, unauthenticated malicious user, with the knowledge of a target user's anti-CSRF token, could potentially exploit this vulnerability by tricking a victim Security Console user to supply malicious HTML or JavaScript code to the vulnerable web application, which code is then executed by the victim's web browser in the context of the vulnerable web application.

CVE-2022-3211
pimcore/pimcore Web
5.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.

CVE-2022-0507
Pandora FMS Web Database
5.8
MEDIUM
EPSS
0.4%
2022 CWE-89 2 PoCs

Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

CVE-2026-25040
budibase Web
5.7
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level user, who normally has no UI permission to invite users, can manipulate API requests to invite new users with any role, including Admin, Creator, or App Viewer, and assign them to any group in the organization. This allows full privilege escalation, bypassing UI restrictions, and can lead to complete takeover of the workspace or organization. As of time of publication, no known fixed versions are available.

CVE-2023-41812
Pandora FMS Web
5.7
MEDIUM
EPSS
0.0%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-21970
BI Publisher (formerly XML Publisher) Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Security). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L

CVE-2023-2630
pimcore/pimcore Web
5.7
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-0028
linagora/twake Web
5.7
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.

CVE-2023-6148
Policy Compliance Connector Jenkins Plugin DevOps Web Cloud
5.7
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access and access to configure or edit jobs to utilize the plugin to configure a potential rouge endpoint via which it was possible to control response for certain request which could be injected with XSS payloads leading to XSS while processing the response data

CVE-2023-6146
Qualysguard Web
5.7
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. 

CVE-2023-0307
thorsten/phpmyfaq Web
5.7
MEDIUM
EPSS
0.8%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-21952
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessibl

CVE-2023-21965
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessibl

CVE-2024-8051
Special Feed Items Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-3059
ENL Newsletter Web Windows
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary Campaigns via a CSRF attack

CVE-2024-8047
Visual Sound (old) Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-8044
infolinks Ad Wrap Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-8043
Vikinghammer Tweet Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-5170
Logo Manager For Enamad Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3972
Similarity Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack