5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-0613
Photo Gallery by 10Web Web Windows
6.1
MEDIUM
EPSS
0.4%
2025 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed

CVE-2025-9034
Wp Edit Password Protected Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2025-56526
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.

CVE-2025-14284
@tiptap/extension-link Web
6.1
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction.

CVE-2025-1286
Download HTML TinyMCE Button Web Windows
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-26408
Wattsense Bridge General
6.1
MEDIUM
EPSS
0.2%
2025 CWE-1191 3 PoCs

The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.

CVE-2025-60280
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly in the browser. When exploited, an attacker can steal session cookies, redirect users to malicious sites, perform actions on behalf of the user, or deface the website. This can lead to user data compromise, loss of user trust, and a broader attack surface for more advanced exploitation techniques.

CVE-2025-20240
Cisco IOS XE Software Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 CWE-692 1 PoC

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

CVE-2025-51541
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to inject malicious JavaScript. This vulnerability can be exploited via a Cross-Site Request Forgery (CSRF) attack due to the absence of CSRF protections on the POST request. An unauthenticated remote attacker can craft a malicious web page that, when visited by a victim, stores the payload persistently in the installation

CVE-2025-61319
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.

CVE-2025-29015
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.

CVE-2025-65790
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline <script> element, the browser executes the attacker-controlled JavaScript.

CVE-2025-11187
OpenSSL General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-787 1 PoC

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations. When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without vali

CVE-2025-67833
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.

CVE-2025-64736
libbiosig General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-125 2 PoCs

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-30745
Oracle MES for Process Manufacturing Web Database
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can

CVE-2025-46173
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.

CVE-2025-20974
PackageInstallerCN General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.

CVE-2025-63735
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

CVE-2025-65215
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field.