5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-56699
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.

CVE-2025-25949
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.

CVE-2025-60916
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.

CVE-2025-26054
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.

CVE-2025-56605
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and echoed back in the HTTP response without sanitization, allowing an attacker to inject and execute arbitrary JavaScript code in the victim's browser.

CVE-2025-27915
🔥 KEV Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
26.1%
2025 0 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an

CVE-2025-55579
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

CVE-2025-51396
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.

CVE-2025-25476
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.

CVE-2025-51401
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.

CVE-2025-13558
Blog2Social: Social Media Auto Post & Scheduler Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the status of arbitrary posts to trash.

CVE-2025-29153
Software Genérico Database
5.4
MEDIUM
EPSS
0.3%
2025 2 PoCs

SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.

CVE-2025-0054
SAP NetWeaver Application Server Java Web
5.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page.

CVE-2025-1231
Server Database
5.4
MEDIUM
EPSS
0.2%
2025 CWE-287 1 PoC

Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.

CVE-2025-50090
Oracle Applications Framework Web Database
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized u

CVE-2025-3230
Mattermost Cloud
5.4
MEDIUM
EPSS
0.2%
2025 CWE-303 1 PoC

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.

CVE-2025-0237
Firefox Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVE-2025-55179
WhatsApp Business for iOS General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.

CVE-2025-46702
Mattermost General
5.4
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the 'Manage Members' permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileg

CVE-2025-57389
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. This vulnerability was fixed in OpenWRT v19.07.0.