38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-3811
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2020-15135
save-server Web
6.7
MEDIUM
EPSS
0.1%
2020 CWE-352 3 PoCs

save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF attack would require you to navigate to a malicious site while you have an active session with Save-Server (Session key stored in cookies). The malicious user would then be able to perform some actions, including uploading/deleting files and adding redirects. If you are logged in as root, this atta

CVE-2020-15145
windows-setup Web Windows
6.7
MEDIUM
EPSS
0.0%
2020 CWE-276 2 PoCs

In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order to get elevated command execution when composer is run by an administrator. 2. A local regular user may create a specially crafted dll in the `C:\ProgramData\ComposerSetup\bin` folder in order to get Local System privileges. See: https://itm4n.github.io/windows-server-netman-dll-hijacking. 3. If the directory of the php.

CVE-2022-21428
FLEXCUBE Universal Banking Web Database
6.7
MEDIUM
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Bankin

CVE-2022-2796
pimcore/pimcore Web
6.7
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.4.

CVE-2021-23814
unisharp/laravel-filemanager Web
6.7
MEDIUM
EPSS
2.1%
2021 CWE-94 3 PoCs

This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an image file, then capture the request 4. Edit the request contents with a malicious file (webshell) 5. Enter the path of file uploaded on URL - Remote Code Execution **Note:** Prevention for bad extensions can be done by using a whitelist in the config file(lfm.php). Correspon

CVE-2021-2151
PeopleSoft Enterprise PT PeopleTools Web Database
6.7
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and

CVE-2022-21582
Banking Trade Finance Web Database
6.7
MEDIUM
EPSS
1.3%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2020-37171
TapinRadio Web
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality.

CVE-2022-2885
yetiforcecompany/yetiforcecrm Web
6.7
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2023-0828
Pandora FMS Web
6.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2019-3887
Kernel Web
6.7
MEDIUM
EPSS
0.0%
2019 CWE-863 1 PoC

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

CVE-2022-21578
FLEXCUBE Universal Banking Web Database
6.7
MEDIUM
EPSS
1.3%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Bankin

CVE-2023-24518
Pandora FMS Web
6.7
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.

CVE-2021-3812
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2025-55308
Software Genérico Web Windows
6.7
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.

CVE-2024-0788
SUPERAntiSpyware Pro X Web
6.6
MEDIUM
EPSS
0.0%
2024 CWE-96 1 PoC

SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys driver.

CVE-2018-2380
🔥 KEV SAP CRM Web
6.6
MEDIUM
EPSS
48.8%
2018 3 PoCs

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

CVE-2024-28224
Software Genérico Web
6.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).

CVE-2025-13070
CSV to SortTable Web Windows
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.