38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-31848
Data Loss Prevention (DLP) ePO extension Web
8.4
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension.

CVE-2017-18852
Software Genérico Web
8.4
HIGH
EPSS
0.0%
2017 1 PoC

Certain NETGEAR devices are affected by CSRF and authentication bypass. This affects R7300DST before 1.0.0.54, R8300 before 1.0.2.100_1.0.82, R8500 before 1.0.2.100_1.0.82, and WNDR3400v3 before 1.0.1.14.

CVE-2024-28143
Scan2Net Web
8.4
HIGH
EPSS
0.1%
2024 CWE-620 2 PoCs

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.

CVE-2025-34114
OpenBlow Web
8.4
HIGH
EPSS
0.0%
2025 CWE-749 2 PoCs

A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple versions and default deployments, due to the absence of critical HTTP response headers including Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, and Cross-Origin-Resource-Policy. This omission weakens browser-level defenses and exposes users to cross-site scripting (XSS), clickjacking, and referer leakage. Although some instances attempt to enforce CSP via HTML <meta> tags, this method is ineffective, as modern browsers rely on header-base

CVE-2025-34188
Print Virtual Appliance Host Web
8.4
HIGH
EPSS
0.1%
2025 CWE-532 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local logging mechanism. Authentication session tokens, including PHPSESSID, XSRF-TOKEN, and laravel_session, are stored in cleartext within world-readable log files. Any local user with access to the machine can extract these session tokens and use them to authenticate remotely to the SaaS environment, bypassing normal login credentials, potentially leading to unauthorized system access and exposure of sensitiv

CVE-2021-33702
SAP NetWeaver Enterprise Portal Web
8.3
HIGH
EPSS
0.7%
2021 CWE-79 1 PoC

Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.

CVE-2023-40288
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-1880
thorsten/phpmyfaq Web ⚡ nuclei
8.3
HIGH
EPSS
14.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-40287
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-45744
Smart Reader Web
8.3
HIGH
EPSS
0.7%
2023 CWE-284 2 PoCs

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to configuration modification. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVE-2024-5420
utnserver Pro Web ⚡ nuclei
8.3
HIGH
EPSS
46.6%
2024 CWE-79 6 PoCs

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CVE-2024-27971
Premmerce Permalink Manager for WooCommerce Web
8.3
HIGH
EPSS
67.4%
2024 CWE-98 1 PoC

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.

CVE-2023-4196
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-26153
geokit-rails Web
8.3
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.

CVE-2024-41671
twisted Web
8.3
HIGH
EPSS
0.1%
2024 CWE-444 1 PoC

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

CVE-2012-10018
Mapplic Lite Web Windows ⚡ nuclei
8.3
HIGH
EPSS
3.4%
2012 CWE-918 2 PoCs

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

CVE-2025-26529
moodle Web
8.3
HIGH
EPSS
1.0%
2025 CWE-79 1 PoC

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

CVE-2025-3776
Verification SMS with TargetSMS Web Windows
8.3
HIGH
EPSS
0.7%
2025 CWE-94 1 PoC

The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().

CVE-2023-1527
tsolucio/corebos Web
8.3
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2024-35219
openapi-generator Web ⚡ nuclei
8.3
HIGH
EPSS
53.2%
2024 CWE-22 0 PoCs

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.