38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-21434
Galaxy Store Web
6.2
MEDIUM
EPSS
0.7%
2023 CWE-20 1 PoC

Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.

CVE-2024-27159
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.0%
2024 CWE-798 2 PoCs

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-20884
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.2%
2024 1 PoC

Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

CVE-2024-34655
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

CVE-2021-21290
netty Web
6.2
MEDIUM
EPSS
0.0%
2021 CWE-378 4 PoCs

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set

CVE-2023-3581
Mattermost Web
6.2
MEDIUM
EPSS
0.2%
2023 CWE-346 1 PoC

Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.

CVE-2021-23980
Mozilla Bleach Web
6.1
MEDIUM
EPSS
0.5%
2021 1 PoC

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

CVE-2025-26159
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 2 PoCs

Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.

CVE-2021-25926
sickrage Web
6.1
MEDIUM
EPSS
0.3%
2021 2 PoCs

In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to masquerade as a victim user, to carry out any actions in the context of the user.

CVE-2025-30746
Oracle iStore Web Database
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle

CVE-2021-37216
Storage Manager XN8008T Web ⚡ nuclei
6.1
MEDIUM
EPSS
11.0%
2021 CWE-79 0 PoCs

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

CVE-2025-14312
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-42551
NetBiblio WebOPAC Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.7%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.

CVE-2025-67291
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.

CVE-2021-2408
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Notification Configuration). The supported version that is affected is 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized u

CVE-2021-24432
Advanced AJAX Product Filters Web Windows
6.1
MEDIUM
EPSS
0.4%
2021 1 PoC

The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.

CVE-2021-31852
McAfee Policy Auditor Web
6.1
MEDIUM
EPSS
0.9%
2021 CWE-79 1 PoC

A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extract of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.

CVE-2021-2043
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.8%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert o

CVE-2021-2140
Financial Services Analytical Applications Infrastructure Web Database
6.1
MEDIUM
EPSS
0.8%
2021 1 PoC

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Rules Framework). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significant

CVE-2025-63714
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of user-supplied input when rendering generated account data to the DOM, allowing persistent injection of malicious HTML elements that execute when clicked by users.