38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-55287
genealogy Web
8.0
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another user’s session, leading to session hijacking, data theft, and UI manipulation. This vulnerability is fixed in 4.4.0.

CVE-2022-45938
Software Genérico Web
8.0
HIGH
EPSS
21.1%
2022 1 PoC

An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..

CVE-2024-13918
Laravel Framework Web
8.0
HIGH
EPSS
1.1%
2024 CWE-79 1 PoC

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.

CVE-2021-3985
kevinpapst/kimai2 Web
8.0
HIGH
EPSS
0.4%
2021 CWE-79 1 PoC

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-3745
flatcore/flatcore-cms Web
8.0
HIGH
EPSS
0.4%
2021 CWE-434 1 PoC

flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2024-46486
Software Genérico Web
8.0
HIGH
EPSS
1.7%
2024 1 PoC

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

CVE-2021-32819
squirrelly Web ⚡ nuclei
8.0
HIGH
EPSS
89.6%
2021 CWE-200 1 PoC

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

CVE-2022-2418
Web Manager Web
8.0
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used.

CVE-2022-0269
yetiforcecompany/yetiforcecrm Web
8.0
HIGH
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

CVE-2025-22389
Software Genérico Web
8.0
HIGH
EPSS
0.4%
2025 CWE-434 1 PoC

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, including .docm .html. When accessed by application users, these files can be used to execute malicious actions or compromise users' systems.

CVE-2022-4839
usememos/memos Web
8.0
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2021-23271
TIBCO EBX Web
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.12 and below.

CVE-2022-0723
microweber/microweber Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-0121
hoppscotch/hoppscotch Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

CVE-2022-4271
osticket/osticket Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

CVE-2022-22776
TIBCO BusinessConnect Trading Community Management Web
8.0
HIGH
EPSS
0.6%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

CVE-2024-13919
Laravel Framework Web
8.0
HIGH
EPSS
0.3%
2024 CWE-79 1 PoC

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

CVE-2024-6508
Software Genérico Web
8.0
HIGH
EPSS
1.0%
2024 CWE-331 1 PoC

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

CVE-2022-2514
beancount/fava Web
8.0
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

CVE-2014-100005
🔥 KEV Software Genérico Web Networking
8.0
HIGH
EPSS
45.9%
2014 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.