5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33405
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
51.4%
2023 1 PoC

Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

CVE-2023-20019
Cisco BroadWorks Web Networking
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow

CVE-2023-33985
SAP NetWeaver Enterprise Portal Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2023-24278
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
64.9%
2023 1 PoC

Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.

CVE-2023-26773
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 3 PoCs

Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file.

CVE-2023-37580
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
93.9%
2023 0 PoCs

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

CVE-2023-23077
Software Genérico Web
6.1
MEDIUM
EPSS
25.7%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.

CVE-2023-4826
socialdriver Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.

CVE-2023-39513
cacti Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `host.php` is used to monitor and manage hosts in the _cacti_ app, hence displays useful information such as data queries and verbose logs. _CENSUS_ found that an adversary that is able to configure a data-quer

CVE-2023-22042
Applications Framework Web Database
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized upda

CVE-2023-2571
Quiz Maker Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1413
WP VR Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2503
10Web Social Post Feed Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-23286
Software Genérico Web
6.1
MEDIUM
EPSS
3.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form.

CVE-2023-2339
pimcore/pimcore Web
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-5631
🔥 KEV Roundcubemail Web
6.1
MEDIUM
EPSS
84.4%
2023 CWE-79 2 PoCs

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVE-2023-7228
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.

CVE-2023-23491
Quick Event Manager WordPress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
11.1%
2023 1 PoC

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

CVE-2023-21496
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.2%
2023 CWE-489 1 PoC

Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.

CVE-2023-51067
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.