5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-45055
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

CVE-2025-26056
Software Genérico General
5.4
MEDIUM
EPSS
0.6%
2025 1 PoC

A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.

CVE-2025-1627
Qi Blocks Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-6557
Chrome Windows
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-45315
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.

CVE-2025-44186
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 2 PoCs

SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

CVE-2025-50108
Oracle Hyperion Financial Reporting Web Database
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected is 11.2.20.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthori

CVE-2025-50363
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

CVE-2025-25476
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.

CVE-2025-1626
Qi Blocks Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-20973
Secure Folder General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.

CVE-2025-67282
Software Genérico General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

CVE-2025-50061
Primavera P6 Enterprise Project Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.0-20.12.21, 21.12.0-21.12.21, 22.12.0-22.12.19, 23.12.0-23.12.13 and 24.12.0-24.12.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfoli

CVE-2025-2475
Mattermost General
5.4
MEDIUM
EPSS
0.2%
2025 CWE-303 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.

CVE-2025-44185
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 3 PoCs

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.

CVE-2025-13097
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-25747
Software Genérico Web
5.4
MEDIUM
EPSS
1.6%
2025 2 PoCs

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

CVE-2025-46171
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.

CVE-2025-12908
Chrome General
5.4
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-50592
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.