5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0742
answerdev/answer Web
8.0
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-26218
TIBCO Nimbus Web
8.0
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.6.0 and below.

CVE-2024-46486
Software Genérico Web
8.0
HIGH
EPSS
1.7%
2024 1 PoC

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

CVE-2024-13918
Laravel Framework Web
8.0
HIGH
EPSS
1.1%
2024 CWE-79 1 PoC

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.

CVE-2024-28157
Jenkins GitBucket Plugin DevOps Web
8.0
HIGH
EPSS
3.7%
2024 1 PoC

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

CVE-2024-51240
Software Genérico Web
8.0
HIGH
EPSS
0.0%
2024 1 PoC

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package

CVE-2024-52951
Software Genérico Web
8.0
HIGH
EPSS
0.1%
2024 3 PoCs

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVE-2024-33788
Software Genérico Web
8.0
HIGH
EPSS
2.6%
2024 1 PoC

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

CVE-2024-45264
Software Genérico Web
8.0
HIGH
EPSS
9.3%
2024 1 PoC

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.

CVE-2024-6508
Software Genérico Web
8.0
HIGH
EPSS
1.0%
2024 CWE-331 1 PoC

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

CVE-2024-1845
VikRentCar Car Rental Management System Web Windows
8.0
HIGH
EPSS
0.3%
2024 1 PoC

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-4835
GitLab DevOps Web
8.0
HIGH
EPSS
7.5%
2024 CWE-79 1 PoC

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVE-2024-13919
Laravel Framework Web
8.0
HIGH
EPSS
0.3%
2024 CWE-79 1 PoC

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

CVE-2024-0778
ISC 2500-S Web
8.0
HIGH
EPSS
49.7%
2024 CWE-78 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this issue is the function setNatConfig of the file /Interface/DevManage/VM.php. The manipulation of the argument natAddress/natPort/natServerPort leads to os command injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251696. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that t

CVE-2019-17333
TIBCO EBX Web
8.0
HIGH
EPSS
0.4%
2019 1 PoC

The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7.

CVE-2019-5130
Foxit Web
8.0
HIGH
EPSS
3.9%
2019 CWE-416 1 PoC

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVE-2021-23273
TIBCO Spotfire Analyst Web Cloud
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.1

CVE-2021-39170
pimcore Web
8.0
HIGH
EPSS
0.0%
2021 CWE-116 1 PoC

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

CVE-2021-23271
TIBCO EBX Web
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.12 and below.

CVE-2021-32819
squirrelly Web ⚡ nuclei
8.0
HIGH
EPSS
89.6%
2021 CWE-200 1 PoC

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.