5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-45754
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.

CVE-2025-25620
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2025 1 PoC

Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.

CVE-2025-55580
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8.

CVE-2025-25747
Software Genérico Web
5.4
MEDIUM
EPSS
1.6%
2025 2 PoCs

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

CVE-2025-50061
Primavera P6 Enterprise Project Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.0-20.12.21, 21.12.0-21.12.21, 22.12.0-22.12.19, 23.12.0-23.12.13 and 24.12.0-24.12.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfoli

CVE-2025-5093
Responsive Lightbox & Gallery Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-63260
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

CVE-2025-2562
Remote Desktop Manager Windows
5.4
MEDIUM
EPSS
0.3%
2025 CWE-778 1 PoC

Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.

CVE-2025-12359
Responsive Lightbox & Gallery Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

CVE-2025-44109
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

CVE-2025-30342
OpenSlides Web
5.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element, it is properly encoded when reflected; however, adding attributes to links is possible, which allows the injection of JavaScript via the onmouseover attribute and others. When a user moves the mouse over such a prepared link, JavaScript is executed in that user's session.

CVE-2025-27933
Mattermost General
5.4
MEDIUM
EPSS
0.3%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public

CVE-2025-67834
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.

CVE-2025-52379
Software Genérico Networking
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerability in the firmware update feature. The /web/um_fileName_set.cgi and /web/um_web_upgrade.cgi endpoints fail to properly sanitize the upgradeFileName parameter, allowing authenticated attackers to execute arbitrary OS commands on the device, resulting in remote code execution.

CVE-2025-29632
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2025 2 PoCs

Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components

CVE-2025-0480
wuzhicms Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-918 1 PoC

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-56146
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

CVE-2025-11486
Farm Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /buyNow.php. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

CVE-2025-10840
Pet Grooming Management Software Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown function of the file /admin/print-payment.php. This manipulation of the argument sql111 causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-9686
i-Educar Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component Listagem de áreas de conhecimento Page. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.