38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-44728
Software Genérico Web
7.6
HIGH
EPSS
0.4%
2024 1 PoC

Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.

CVE-2024-46610
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2024 1 PoC

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

CVE-2022-0877
bookstackapp/bookstack Web
7.6
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.

CVE-2023-32741
Contact Form to Any API Web Database
7.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.

CVE-2023-1238
answerdev/answer Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-3552
nilsteampassnet/teampass Web
7.6
HIGH
EPSS
0.3%
2023 CWE-116 1 PoC

Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2020-11466
Software Genérico Web
7.6
HIGH
EPSS
0.4%
2020 1 PoC

An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally, it leaked ticket authentication code, making it possible to make changes to a ticket.

CVE-2023-1536
answerdev/answer Web
7.6
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.

CVE-2023-5865
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.3%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

CVE-2023-26439
OX App Suite Web Database
7.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.

CVE-2023-0790
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.4%
2023 CWE-248 1 PoC

Uncaught Exception in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2025-46349
yeswiki Web ⚡ nuclei
7.6
HIGH
EPSS
0.5%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.

CVE-2021-2013
BI Publisher (formerly XML Publisher) Web Database
7.6
HIGH
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unautho

CVE-2021-23404
sqlite-web Web Database
7.6
HIGH
EPSS
0.1%
2021 1 PoC

This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.

CVE-2023-3070
tsolucio/corebos Web
7.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

CVE-2024-6205
PayPlus Payment Gateway Web Database Windows ⚡ nuclei
7.6
HIGH
EPSS
90.4%
2024 2 PoCs

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

CVE-2021-2051
BI Publisher (formerly XML Publisher) Web Database
7.6
HIGH
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauth

CVE-2020-26205
Sal Web
7.6
HIGH
EPSS
0.2%
2020 CWE-79 1 PoC

Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.

CVE-2022-1238
radareorg/radare2 Web
7.6
HIGH
EPSS
0.3%
2022 CWE-787 2 PoCs

Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

CVE-2021-2380
Applications Framework Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorize