1708 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-39601
Custom CSS, JS & PHP Web
9.6
CRITICAL
EPSS
0.0%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through <= 2.4.1.

CVE-2025-32641
Anant Addons for Elementor Web
9.6
CRITICAL
EPSS
0.1%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.

CVE-2025-56683
Software Genérico Web
9.6
CRITICAL
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted README.md file.

CVE-2020-7357
Cayin CMS-SE Web
9.6
CRITICAL
EPSS
77.2%
2020 CWE-78 1 PoC

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.

CVE-2020-35391
Software Genérico Web Networking
9.6
CRITICAL
EPSS
46.8%
2020 4 PoCs

Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.

CVE-2020-13564
phpGACL Web
9.6
CRITICAL
EPSS
39.5%
2020 CWE-80 1 PoC

A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template acl_id parameter.

CVE-2020-13562
phpGACL Web
9.6
CRITICAL
EPSS
71.0%
2020 CWE-80 1 PoC

A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.

CVE-2020-6167
Software Genérico Web Windows
9.6
CRITICAL
EPSS
0.7%
2020 2 PoCs

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.

CVE-2020-13563
phpGACL Web
9.6
CRITICAL
EPSS
39.5%
2020 CWE-80 1 PoC

A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.

CVE-2022-30690
AVideo Web
9.6
CRITICAL
EPSS
9.8%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-41654
Ghost Web
9.6
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-22759
Firefox Web
9.6
CRITICAL
EPSS
0.3%
2022 2 PoCs

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-2733
openemr/openemr Web ⚡ nuclei
9.6
CRITICAL
EPSS
91.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-32772
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
7.8%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "msg" parameter which is inserted into the document with insufficient sanitization.

CVE-2022-32770
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
14.4%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "toast" parameter which is inserted into the document with insufficient sanitization.

CVE-2022-26842
AVideo Web
9.6
CRITICAL
EPSS
9.5%
2022 CWE-79 1 PoC

A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-22114
docs Web
9.6
CRITICAL
EPSS
2.0%
2022 CWE-79 1 PoC

In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are executed in a victim’s browser when they enter the crafted URL. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, by an unauthenticated attacker.

CVE-2022-3152
phpfusion/phpfusion Web
9.6
CRITICAL
EPSS
0.3%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.

CVE-2022-0153
forkcms/forkcms Web Database
9.6
CRITICAL
EPSS
0.3%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

CVE-2022-36180
Software Genérico Web
9.6
CRITICAL
EPSS
0.2%
2022 1 PoC

Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.