38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-45172
Software Genérico Web
6.8
MEDIUM
EPSS
0.5%
2024 3 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site request forgery (CSRF) attacks. The C-MOR web interface offers no protection against cross-site request forgery (CSRF) attacks.

CVE-2023-49965
Software Genérico Web Networking
6.8
MEDIUM
EPSS
0.4%
2023 1 PoC

SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

CVE-2022-4512
Better Font Awesome Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-0954
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
4.3%
2022 CWE-79 1 PoC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2023-30962
com.palantir.acme.cerberus:cerberus Web
6.8
MEDIUM
EPSS
0.6%
2023 CWE-434 1 PoC

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2023-0378
Greenshift Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-46369
FTP server Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields.

CVE-2024-37085
🔥 KEV VMware ESXi Web Windows
6.8
MEDIUM
EPSS
75.1%
2024 4 PoCs

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVE-2022-1163
mineweb/minewebcms Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 3 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.

CVE-2024-5676
IP150 Internet Module Web
6.8
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.

CVE-2024-5077
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-2761
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

CVE-2025-3742
Responsive Lightbox & Gallery Web Windows
6.8
MEDIUM
EPSS
0.3%
2025 1 PoC

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4422
cockpit-hq/cockpit Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2024-6021
Donation Block For PayPal Web Windows
6.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability

CVE-2021-29484
Ghost Web ⚡ nuclei
6.8
MEDIUM
EPSS
57.0%
2021 CWE-79 1 PoC

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've visited a malicious site. Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version between 4.0.0 and 4.3.2. Immediate action should be taken to secure

CVE-2022-47909
Checkmk Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-20 1 PoC

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.

CVE-2023-20116
Cisco Unified Communications Manager Web Networking
6.8
MEDIUM
EPSS
0.5%
2023 CWE-835 1 PoC

A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow the attacker to cause a DoS conditi

CVE-2024-12227
Dragon Center Web
6.8
MEDIUM
EPSS
0.1%
2024 CWE-476 1 PoC

A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the function MmUnMapIoSpace in the library NTIOLib_X64.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. Upgrading to version 2.0.148.0 is able to address this issue. It is recommended to upgrade the affected component.