2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-25270
SOCA Access Control System Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logged_page.php that allows attackers to inject malicious scripts. Attackers can exploit this weakness by sending crafted POST requests to execute arbitrary HTML and script code in a victim's browser session.

CVE-2019-25384
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the EXT, SRC_PORT_SEL, SRC_PORT, DEST_IP, DEST_PORT_SEL, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.

CVE-2019-25448
OrientDB Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating users with script payloads in the name parameter. Attackers can send POST requests to the document endpoint with JavaScript code in the name field to execute arbitrary scripts when users view the application.

CVE-2019-25429
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the openvpn_advanced endpoint. Attackers can inject JavaScript code through the GLOBAL_NETWORKS and GLOBAL_DNS parameters via POST requests to execute arbitrary scripts in users' browsers.

CVE-2019-25312
InoERP Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.

CVE-2019-25449
OrientDB Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON payloads to the document endpoint. Attackers can send POST requests to /document/demodb/-1:-1 with script tags in the name parameter to execute arbitrary JavaScript in users' browsers.

CVE-2019-25378
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi endpoint that allow attackers to inject malicious scripts through parameters including CACHE_SIZE, MAX_SIZE, MIN_SIZE, MAX_OUTGOING_SIZE, and MAX_INCOMING_SIZE. Attackers can submit POST requests with script payloads to store or reflect arbitrary JavaScript code that executes in users' browsers when the proxy configuration page is accessed.

CVE-2019-25280
Yahei-PHP Prober Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 2 PoCs

Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML code through the 'speed' GET parameter. Attackers can inject malicious HTML code in the 'speed' parameter of prober.php to trigger cross-site scripting in user browser sessions.

CVE-2019-25399
IPFire Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject malicious scripts through the FS, PATH, and UUID parameters. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.

CVE-2019-25242
FaceSentry Access Control System Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-352 2 PoCs

FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated users into loading a specially crafted webpage.

CVE-2019-25404
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input through admin management parameters. Attackers can inject script payloads in the admin_name, name, and surname parameters via POST requests to the /korugan/admins endpoint, which are stored and executed when administrators access the interface.

CVE-2019-25301
Millhouse Project Web Database
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality that allows attackers to inject malicious scripts. Attackers can post comments with embedded JavaScript through the 'content' parameter in add_comment_sql.php to execute arbitrary scripts in victim browsers.

CVE-2019-25393
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation. Attackers can submit POST requests to the smoothinfo.cgi endpoint with script payloads in the WRAP or SECTIONTITLE parameters to execute arbitrary JavaScript in victim browsers.

CVE-2019-25426
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the dnsmasq endpoint. Attackers can send POST requests with script payloads in the TRANSPARENT_SOURCE_BYPASS or TRANSPARENT_DESTINATION_BYPASS parameters to execute arbitrary JavaScript in users' browsers.

CVE-2019-25385
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT parameters. Attackers can send POST requests to the outgoing.cgi endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.

CVE-2019-25388
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the ipblock.cgi endpoint. Attackers can inject script tags through the SRC_IP and COMMENT parameters in POST requests to execute arbitrary JavaScript in users' browsers.

CVE-2019-25373
OPNsense Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the category parameter. Attackers can send POST requests to firewall_rules_edit.php with script payloads in the category field to execute arbitrary JavaScript in the browsers of other users accessing firewall rule pages.

CVE-2019-25413
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the /manage/ips/rules/ endpoint with script payloads in the ID parameter to execute arbitrary JavaScript in victim browsers.

CVE-2019-25375
OPNsense Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the mailserver parameter. Attackers can send POST requests to the monit interface with JavaScript payloads in the mailserver parameter to execute arbitrary code in users' browsers.

CVE-2019-25233
DOMINAplus Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 2 PoCs

AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions.