38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-2723
FLEXCUBE Investor Servicing Web Database
7.1
HIGH
EPSS
0.5%
2020 1 PoC

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Investor Servicing accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXC

CVE-2025-8281
WP Talroo Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.

CVE-2024-13668
WordPress Activity O Meter Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2025-2957
TEW-411BRP+ Web
7.1
HIGH
EPSS
0.1%
2025 CWE-476 1 PoC

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-29931
WP Go Maps Web ⚡ nuclei
7.1
HIGH
EPSS
12.9%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

CVE-2024-55546
IAP-420 Web
7.1
HIGH
EPSS
0.2%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2023-22710
Return and Warranty Management System for WooCommerce Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCommerce plugin <= 1.2.3 versions.

CVE-2020-2942
Financial Services Price Creation and Discovery Web Database
7.1
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Price Creation and Discovery accessible data as well as unauthorized read

CVE-2024-41357
Software Genérico Web
7.1
HIGH
EPSS
2.2%
2024 1 PoC

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

CVE-2021-47782
Odine Solutions GateKeeper Web Database
7.1
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.

CVE-2023-35918
Bulk Stock Management Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions.

CVE-2024-13863
Stylish Google Sheet Reader 4.0 Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-30489
Email Subscription Popup Web
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.

CVE-2019-25573
Green CMS Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat parameter to manipulate database queries and extract sensitive information.

CVE-2024-12708
Bulk Me Now! Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-53775
Screen SFT DAB Series - Compact Radio DAB Transmitter Web
7.1
HIGH
EPSS
0.2%
2023 CWE-384 2 PoCs

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.

CVE-2024-12878
Custom Block Builder Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.7%
2024 1 PoC

The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13330
JustRows free Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-56917
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVE-2021-22224
GitLab DevOps Web
7.1
HIGH
EPSS
0.4%
2021 1 PoC

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim