38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-4103
vanessa219/vditor Web
6.8
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.

CVE-2024-5744
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-4305
Post Grid Gutenberg Blocks and WordPress Blog Plugin Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2020-15156
nodebb-plugin-blog-comments Web
6.8
MEDIUM
EPSS
0.2%
2020 CWE-352 1 PoC

In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.

CVE-2021-22238
GitLab DevOps Web
6.8
MEDIUM
EPSS
1.2%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVE-2023-0075
Amazon JS Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-1163
mineweb/minewebcms Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 3 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.

CVE-2022-0911
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2023-1033
froxlor/froxlor Web
6.8
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.

CVE-2024-37600
Software Genérico Web
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address, an attacker can connect via the internal network to the Service Broker service. With prepared HTTP requests, an attacker can cause the Service-Broker service to fail.

CVE-2023-4652
instantsoft/icms2 Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2025-27448
Endress+Hauser MEAC300-FNADE4 Web
6.8
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.

CVE-2023-49923
Enterprise Search Web
6.8
MEDIUM
EPSS
0.4%
2023 CWE-532 1 PoC

An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to DEBUG, which is disabled by default.

CVE-2024-3710
Image Photo Gallery Final Tiles Grid Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2020-14757
WebLogic Server Web Database
6.8
MEDIUM
EPSS
1.5%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). The supported version that is affected is 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data

CVE-2024-5284
wp-affiliate-platform Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13347
Essential WP Real Estate Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2020-15189
soycms Web
6.8
MEDIUM
EPSS
5.0%
2020 CWE-434 1 PoC

SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328.

CVE-2024-3901
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

CVE-2022-0954
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
4.3%
2022 CWE-79 1 PoC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.