38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0505
microweber/microweber Web
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-24926
SmartTagPlugin Web
5.7
MEDIUM
EPSS
0.4%
2022 CWE-20 1 PoC

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

CVE-2021-35494
TIBCO JasperReports Server Web Cloud
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contain a race condition that allows a low privileged authenticated attacker via the REST API to obtain read access to temporary objects created by other users on the affected system. Affected rel

CVE-2023-2630
pimcore/pimcore Web
5.7
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2021-36094
((OTRS)) Community Edition Web
5.7
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

CVE-2021-2445
Hyperion Infrastructure Technology Web Database
5.7
MEDIUM
EPSS
1.3%
2021 1 PoC

Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as unau

CVE-2022-21609
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessi

CVE-2022-0231
livehelperchat/livehelperchat Web
5.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2019-11858
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2019 1 PoC

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

CVE-2020-14617
Primavera Unifier Web Database
5.7
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App). Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and 19.12; Mobile App: Prior to 20.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.

CVE-2024-57277
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2024 1 PoC

InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

CVE-2025-63952
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

CVE-2023-0028
linagora/twake Web
5.7
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.

CVE-2023-6148
Policy Compliance Connector Jenkins Plugin DevOps Web Cloud
5.7
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access and access to configure or edit jobs to utilize the plugin to configure a potential rouge endpoint via which it was possible to control response for certain request which could be injected with XSS payloads leading to XSS while processing the response data

CVE-2022-1648
Pandora FMS Web
5.7
MEDIUM
EPSS
2.8%
2022 CWE-23 1 PoC

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.

CVE-2024-44674
Software Genérico Web
5.7
MEDIUM
EPSS
3.8%
2024 1 PoC

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

CVE-2024-2101
Salon booking system Web Windows
5.7
MEDIUM
EPSS
0.7%
2024 1 PoC

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.

CVE-2023-6146
Qualysguard Web
5.7
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. 

CVE-2023-0307
thorsten/phpmyfaq Web
5.7
MEDIUM
EPSS
0.8%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2024-3972
Similarity Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack