38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-36918
SAP Enable Now Web
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information.

CVE-2024-41504
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.

CVE-2024-8056
MM-Breaking News Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2023-4294
URL Shortify Web Windows
6.1
MEDIUM
EPSS
32.4%
2023 2 PoCs

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVE-2024-28276
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.

CVE-2022-45176
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.

CVE-2024-27719
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function.

CVE-2024-52882
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.

CVE-2024-6651
WordPress File Upload Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
18.5%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-0239
Contact Form 7 Connector Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.

CVE-2022-23397
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2022 0 PoCs

The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."

CVE-2024-21030
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-50969
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.

CVE-2024-6334
Easy Table of Contents Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-8883
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.6%
2024 CWE-601 2 PoCs

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

CVE-2022-4552
FL3R FeelBox Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-48903
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.

CVE-2025-63499
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

CVE-2024-27743
Software Genérico Web
6.1
MEDIUM
EPSS
3.0%
2024 1 PoC

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component.

CVE-2025-28073
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.