2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-7246
System Dashboard Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
1.5%
2023 1 PoC

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

CVE-2022-44949
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.

CVE-2024-36837
Software Genérico Web Database ⚡ nuclei
5.4
MEDIUM
EPSS
91.7%
2024 2 PoCs

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

CVE-2024-4940
gradio-app/gradio Web ⚡ nuclei
5.4
MEDIUM
EPSS
7.2%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

CVE-2023-28665
Woo Bulk Price Update WordPress Plugin Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
21.8%
2023 1 PoC

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

CVE-2023-1318
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2024-7008
Calibre Web ⚡ nuclei
5.4
MEDIUM
EPSS
13.4%
2024 CWE-79 1 PoC

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

CVE-2023-2745
WordPress Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
77.2%
2023 CWE-22 2 PoCs

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CVE-2025-27915
🔥 KEV Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
26.1%
2025 0 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an

CVE-2023-1317
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2025-27506
nocodb Web ⚡ nuclei
5.4
MEDIUM
EPSS
3.8%
2025 CWE-79 0 PoCs

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw occurs due to implementation of the client-side template engine ejs, specifically on file resetPassword.ts where the template is using the insecure function “<%-“, which is rendered by the function renderPasswordReset. This vulnerability is fixed in 0.258.0.

CVE-2022-44947
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.1%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add".

CVE-2023-1315
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
10.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-0552
Registration Forms Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
16.4%
2023 1 PoC

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

CVE-2022-43167
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
5.9%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVE-2022-36923
Software Genérico Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
32.5%
2022 0 PoCs

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

CVE-2023-26843
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
12.4%
2023 1 PoC

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.

CVE-2022-4306
Panda Pods Repeater Field Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.3%
2022 1 PoC

The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.

CVE-2024-13099
Widget4Call Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
4.3%
2024 1 PoC

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2022-44946
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.