38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-56917
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVE-2024-12878
Custom Block Builder Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.7%
2024 1 PoC

The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13330
JustRows free Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.8%
2024 1 PoC

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-47782
Odine Solutions GateKeeper Web Database
7.1
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.

CVE-2021-22224
GitLab DevOps Web
7.1
HIGH
EPSS
0.4%
2021 1 PoC

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVE-2024-13884
Limit Bio Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12019
LogicalDOC Community Web
7.1
HIGH
EPSS
0.2%
2024 CWE-23 1 PoC

The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read’ and ‘download’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to read the contents of any file available within the privileges of the system user running the application.

CVE-2019-25573
Green CMS Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat parameter to manipulate database queries and extract sensitive information.

CVE-2023-47115
label-studio Web ⚡ nuclei
7.1
HIGH
EPSS
3.2%
2023 CWE-79 0 PoCs

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. The file `users/fu

CVE-2024-13632
WP Extra Fields Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2020-9049
victor Web Client version 5.6 and prior Web
7.1
HIGH
EPSS
0.1%
2020 CWE-285 1 PoC

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.

CVE-2024-29931
WP Go Maps Web ⚡ nuclei
7.1
HIGH
EPSS
12.9%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

CVE-2024-13881
Link My Posts Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-30875
Software Genérico Web
7.1
HIGH
EPSS
19.8%
2024 1 PoC

Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQuery UI.

CVE-2023-27264
Mattermost Web
7.1
HIGH
EPSS
0.1%
2023 CWE-862 1 PoC

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.

CVE-2019-25703
ImpressCMS Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.

CVE-2024-13569
Front End Users Web Windows ⚡ nuclei
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-8281
WP Talroo Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.

CVE-2022-32510
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-45365
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
20.1%
2022 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.