5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-60313
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 2 PoCs

Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker to execute arbitrary code.

CVE-2025-7022
My Reservation System Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-57444
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description parameter.

CVE-2025-63830
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

CVE-2025-52277
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field

CVE-2025-51858
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.

CVE-2025-32970
xwiki-platform General ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2025 CWE-601 0 PoCs

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.

CVE-2025-45314
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function.

CVE-2025-28121
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2025 1 PoC

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

CVE-2025-14372
Chrome General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-416 1 PoC

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-43952
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.

CVE-2025-56008
Software Genérico Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

CVE-2025-61087
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

CVE-2025-51967
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

CVE-2025-45960
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding

CVE-2025-65231
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.

CVE-2025-63714
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of user-supplied input when rendering generated account data to the DOM, allowing persistent injection of malicious HTML elements that execute when clicked by users.

CVE-2025-60374
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users viewing the chat, resulting in client-side code execution, potential session token theft, and other malicious actions. A different vulnerability than CVE-2024-8867.

CVE-2025-14312
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-50073
Oracle WebLogic Server DevOps Web Database
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorize