38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-34469
Software Genérico Web
7.1
HIGH
EPSS
1.2%
2024 1 PoC

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

CVE-2020-14709
Retail Customer Management and Segmentation Foundation Web Database
7.1
HIGH
EPSS
0.2%
2020 1 PoC

Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Card). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Custome

CVE-2022-0926
microweber/microweber Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2024-13626
VR-Frases (collect & share quotes) Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2022-0087
keystonejs/keystone Web ⚡ nuclei
7.1
HIGH
EPSS
56.1%
2022 CWE-79 1 PoC

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2023-2591
nilsteampassnet/teampass Web
7.1
HIGH
EPSS
0.3%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2025-63589
Software Genérico Web Networking
7.1
HIGH
EPSS
0.0%
2025 1 PoC

A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the URL path is reflected into multiple HTML elements, allowing execution of arbitrary JavaScript in victims' browsers visiting a crafted URL.

CVE-2020-2942
Financial Services Price Creation and Discovery Web Database
7.1
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Price Creation and Discovery accessible data as well as unauthorized read

CVE-2023-32961
Zotpress Web
7.1
HIGH
EPSS
4.7%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.

CVE-2023-30868
CMS Tree Page View Web ⚡ nuclei
7.1
HIGH
EPSS
54.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

CVE-2025-66835
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2025 1 PoC

TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.

CVE-2024-29931
WP Go Maps Web ⚡ nuclei
7.1
HIGH
EPSS
12.9%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

CVE-2020-2937
Insurance Accounting Analyzer Web Database
7.1
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Insurance Accounting Analyzer product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Accounting Analyzer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Accounting Analyzer accessible data as well as unauthorized read access to a subset of Oracle Insurance Account

CVE-2021-1257
Cisco Digital Network Architecture Center (DNA Center) Web Networking
7.1
HIGH
EPSS
0.1%
2021 CWE-352 1 PoC

A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a web-based management user to follow a specially crafted link. A successful exploit could allow the attacker to perform arbitrary

CVE-2024-13876
mEintopf Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2020-2939
Financial Services Asset Liability Management Web Database
7.1
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 and 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Asset Liability Management accessible data as well as unauthorized r

CVE-2023-37988
Contact Form Generator Web ⚡ nuclei
7.1
HIGH
EPSS
21.8%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

CVE-2018-25207
Online Quiz Maker Web Database
7.1
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to extract sensitive database information or bypass authentication.

CVE-2019-25503
PHPads Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bannerID parameter in click.php3. Attackers can submit crafted bannerID values using SQL comment syntax and functions like extractvalue to extract sensitive database information such as the current database name.