38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-31629
PHP Web
6.5
MEDIUM
EPSS
15.4%
2022 CWE-20 2 PoCs

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVE-2022-2174
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
27.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

CVE-2024-47630
ElementInvader Addons for Elementor Web
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.2.7.

CVE-2022-2130
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
46.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2024-0679
ColorMag Web Windows
6.5
MEDIUM
EPSS
9.8%
2024 CWE-862 1 PoC

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.

CVE-2025-50867
Software Genérico Web Database Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

CVE-2020-2906
PeopleSoft Enterprise SCM Purchasing Web Database
6.5
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Supplier Change). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-45589
Software Genérico Web Cloud
6.5
MEDIUM
EPSS
7.8%
2024 2 PoCs

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

CVE-2021-28861
Software Genérico Web
6.5
MEDIUM
EPSS
1.4%
2021 1 PoC

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVE-2024-6025
Quiz and Survey Master (QSM) Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

CVE-2025-67013
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

CVE-2024-1295
events-calendar-pro Web Windows
6.5
MEDIUM
EPSS
0.9%
2024 1 PoC

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

CVE-2024-2509
Gutenberg Blocks by Kadence Blocks Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-7817
Misiek Photo Album Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack

CVE-2024-21080
Applications Framework Web Database
6.5
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: REST Services). Supported versions that are affected are 12.2.9-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2025-26241
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

CVE-2024-5071
Bookster Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVE-2025-51864
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens.

CVE-2020-14887
FLEXCUBE Universal Banking Web Database
6.5
MEDIUM
EPSS
0.4%
2020 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3.0 and 14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L

CVE-2024-40472
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."