38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-49985
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.

CVE-2025-57055
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using curl_exec() without sufficient validation, allowing the attacker to force internal or external HTTP requests.

CVE-2025-55668
Apache Tomcat Web
6.5
MEDIUM
EPSS
0.0%
2025 CWE-384 1 PoC

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

CVE-2021-2275
Applications Manager Web Database
6.5
MEDIUM
EPSS
1.3%
2021 1 PoC

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Manager acce

CVE-2014-0207
Software Genérico Web
6.5
MEDIUM
EPSS
9.2%
2014 3 PoCs

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVE-2023-35840
Software Genérico Web
6.5
MEDIUM
EPSS
6.3%
2023 1 PoC

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

CVE-2023-42579
Samsung Keyboard Web
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.

CVE-2024-0679
ColorMag Web Windows
6.5
MEDIUM
EPSS
9.8%
2024 CWE-862 1 PoC

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.

CVE-2025-2745
PI Web API Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.

CVE-2022-4363
Wholesale Market Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack

CVE-2023-3073
tsolucio/corebos Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.

CVE-2025-61096
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.

CVE-2022-3232
ikus060/rdiffweb Web
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.

CVE-2023-20891
VMware Tanzu Application Service for VMs Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials and can push new malicious versions of an application. In a default deployment non-admin users do not have access to the platform system audit logs.

CVE-2020-6145
ERPNext Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-4121
yetiforcecompany/yetiforcecrm Web
6.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2019-7004
IP Office Application Server Web
6.4
MEDIUM
EPSS
0.7%
2019 CWE-79 1 PoC

A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.

CVE-2022-47373
Pandora FMS Web
6.4
MEDIUM
EPSS
0.7%
2022 CWE-352 2 PoCs

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.

CVE-2020-15119
lock Web
6.4
MEDIUM
EPSS
0.3%
2020 CWE-79 1 PoC

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

CVE-2020-27226
OpenClinic Web Database
6.4
MEDIUM
EPSS
1.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.