38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-37108
PhpIX 2012 Professional Web Database
7.1
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the 'id' parameter to potentially extract or modify database information.

CVE-2024-13574
XV Random Quotes Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-39646
Custom 404 Pro Web ⚡ nuclei
7.1
HIGH
EPSS
4.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

CVE-2025-14701
Crafty Controller Web
7.1
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

CVE-2025-13072
HandL UTM Grabber / Tracker Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2019-25582
doit CMDB Web
7.1
HIGH
EPSS
0.1%
2019 CWE-434 1 PoC

i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file_manager=image and supply arbitrary file paths like src/config.inc.php to retrieve configuration files and sensitive system data.

CVE-2019-25529
Placeto CMS Web Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using boolean-based blind, time-based blind, or union-based techniques to extract sensitive database information.

CVE-2018-25191
Facturation System Web Database
7.1
HIGH
EPSS
0.0%
2018 CWE-89 1 PoC

Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'mod_id' parameter. Attackers can send POST requests to the editar_producto.php endpoint with crafted SQL payloads in the mod_id parameter to extract sensitive database information including usernames, database names, and version details.

CVE-2024-0672
Pz-LinkCard Web Windows
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2019-25246
N100 H.264 VGA IP Camera Web
7.1
HIGH
EPSS
0.1%
2019 CWE-22 2 PoCs

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying absolute file paths.

CVE-2020-2942
Financial Services Price Creation and Discovery Web Database
7.1
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Price Creation and Discovery accessible data as well as unauthorized read

CVE-2024-10483
Simple:Press Forum Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-55545
IAP-420 Web
7.1
HIGH
EPSS
0.4%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2012-10024
Media Center Web
7.1
HIGH
EPSS
48.8%
2012 CWE-22 1 PoC

XBMC version 11, including builds up to the 2012-11-04 nightly release, contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can exploit this flaw to read arbitrary files from the host filesystem, including sensitive configuration or credential files.

CVE-2025-1436
Limit Bio Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-29137
Tourfic Web ⚡ nuclei
7.1
HIGH
EPSS
16.9%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

CVE-2025-63588
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2025 2 PoCs

An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.

CVE-2025-5034
wp-file-download Web Windows
7.1
HIGH
EPSS
0.2%
2025 1 PoC

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2024-4531
Business Card Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

CVE-2024-22198
nginx-ui Web
7.1
HIGH
EPSS
16.0%
2024 CWE-77 1 PoC

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sending a request to the API. This issue may lead to authenticated remote code execution, privilege escalation, and information disclosure. This vulnerability has been patched in version 2.0.0.beta.9.