38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1726
wenzhixin/bootstrap-table Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVE-2025-25967
Software Genérico Web
6.8
MEDIUM
EPSS
0.4%
2025 1 PoC

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVE-2022-1163
mineweb/minewebcms Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 3 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.

CVE-2023-0541
GS Books Showcase Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-61547
Software Genérico Web
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The application does not implement proper CSRF tokens or other other protective measures, allowing a remote attacker to trick authenticated users into unknowingly executing unintended actions within their session. This can lead to unauthorized data modification such as credential updates.

CVE-2023-2323
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2025-15441
Form Maker by 10Web Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

CVE-2022-4793
Blog Designer Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2025-9698
The Plus Addons for Elementor Web Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.

CVE-2023-0375
Easy Affiliate Links Web Windows
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2616
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-0061
Judge.me Product Reviews for WooCommerce Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-47228
ScriptCase Web Networking
6.7
MEDIUM
EPSS
10.0%
2025 CWE-78 1 PoC

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests.

CVE-2025-55309
Software Genérico Web Windows
6.7
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.

CVE-2022-4845
usememos/memos Web
6.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

CVE-2020-37170
TapinRadio Web
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows local attackers to crash the application. Attackers can overwrite the address field with 3000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality.

CVE-2022-21428
FLEXCUBE Universal Banking Web Database
6.7
MEDIUM
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Bankin

CVE-2026-5944
Cisco Intersight Device Connector for Prism Central Web Networking
6.7
MEDIUM
EPSS
0.1%
2026 CWE-306 1 PoC

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network access can exploit this vulnerability by sending crafted requests to the exposed endpoint to enumerate cluster metadata, including virtual machine information and cluster config

CVE-2021-3811
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-4733
openemr/openemr Web
6.7
MEDIUM
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.