5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-3294
saleor/react-storefront Web
7.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.

CVE-2023-0112
usememos/memos Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-5044
ingress-nginx DevOps Web
7.6
HIGH
EPSS
10.6%
2023 CWE-20 3 PoCs

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

CVE-2023-2534
OTRS Web
7.6
HIGH
EPSS
0.4%
2023 CWE-285 1 PoC

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.

CVE-2023-22060
Hyperion BI+ Web Database
7.6
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Workspace accessible data as well as unauthorized access to c

CVE-2023-41788
Pandora FMS Web
7.6
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allows attackers to execute code via PHP file uploads. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-0308
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-37270
Piwigo Web Database ⚡ nuclei
7.6
HIGH
EPSS
59.2%
2023 CWE-89 0 PoCs

Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be log in to the administrator screen, even with low privileges. Any SQL statement can be executed. Doing so may leak information from the database. Version 13.8.0 contains a fix

CVE-2023-0289
craigk5n/webcalendar Web
7.6
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.

CVE-2023-5043
ingress-nginx Web
7.6
HIGH
EPSS
4.9%
2023 CWE-20 1 PoC

Ingress nginx annotation injection causes arbitrary command execution.

CVE-2023-4347
librenms/librenms Web
7.6
HIGH
EPSS
79.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

CVE-2024-21191
Oracle Enterprise Manager Fusion Middleware Control Web Database
7.6
HIGH
EPSS
0.5%
2024 1 PoC

Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Fusion Middleware Control. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Fusion Middleware Control, attacks may significantly impact additional products (scope change). Su

CVE-2024-42346
galaxy Web
7.6
HIGH
EPSS
10.3%
2024 CWE-79 1 PoC

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-35540
Software Genérico Web
7.6
HIGH
EPSS
8.7%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2024-28320
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2024 2 PoCs

Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.

CVE-2024-35224
openproject Web
7.6
HIGH
EPSS
0.2%
2024 CWE-80 1 PoC

OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header values. This attack requires the permissions "Edit work packages" as well as "Add attachments". A project admin could attempt to escalate their privileges by sending this XSS to a System Admin. Otherwise, if a full System Admin is required, then this attack is significantly less impactful. By utilizing a ticket's attachment, you can store javascript in the a

CVE-2024-46610
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2024 1 PoC

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

CVE-2024-21195
Oracle BI Publisher Web Database
7.6
HIGH
EPSS
0.1%
2024 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to caus

CVE-2024-3405
WP Prayer Web Windows
7.6
HIGH
EPSS
0.2%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-4758
Muslim Prayer Time BD Web Windows
7.6
HIGH
EPSS
0.1%
2024 1 PoC

The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack