13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-2101
Salon booking system Web Windows
5.7
MEDIUM
EPSS
0.7%
2024 1 PoC

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.

CVE-2024-44674
Software Genérico Web
5.7
MEDIUM
EPSS
3.8%
2024 1 PoC

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

CVE-2024-57277
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2024 1 PoC

InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

CVE-2019-11858
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2019 1 PoC

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

CVE-2021-2445
Hyperion Infrastructure Technology Web Database
5.7
MEDIUM
EPSS
1.3%
2021 1 PoC

Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as unau

CVE-2021-36094
((OTRS)) Community Edition Web
5.7
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

CVE-2021-35494
TIBCO JasperReports Server Web Cloud
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contain a race condition that allows a low privileged authenticated attacker via the REST API to obtain read access to temporary objects created by other users on the affected system. Affected rel

CVE-2025-22388
Software Genérico Web
5.7
MEDIUM
EPSS
0.5%
2025 CWE-79 1 PoC

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.

CVE-2025-63952
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

CVE-2020-12781
iTop Web
5.7
MEDIUM
EPSS
0.1%
2020 CWE-352 1 PoC

Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

CVE-2020-14617
Primavera Unifier Web Database
5.7
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App). Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and 19.12; Mobile App: Prior to 20.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.

CVE-2020-2677
Hospitality OPERA 5 Property Services Web Database
5.7
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Login). Supported versions that are affected are 5.5 and 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 accessible data. CVSS 3.0 Base Score 5.7 (Confidentiality impacts). CVS

CVE-2022-24926
SmartTagPlugin Web
5.7
MEDIUM
EPSS
0.4%
2022 CWE-20 1 PoC

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

CVE-2022-0505
microweber/microweber Web
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-3516
librenms/librenms Web
5.7
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-3881
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log Web Windows
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-0268
getgrav/grav Web
5.7
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.

CVE-2022-36859
SmartTagPlugin Web
5.7
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim's devices.

CVE-2022-0963
microweber/microweber Web ⚡ nuclei
5.7
MEDIUM
EPSS
8.3%
2022 CWE-79 1 PoC

Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-1648
Pandora FMS Web
5.7
MEDIUM
EPSS
2.8%
2022 CWE-23 1 PoC

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.