13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0087
keystonejs/keystone Web ⚡ nuclei
7.1
HIGH
EPSS
56.1%
2022 CWE-79 1 PoC

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-21593
HTTP Server Web Database
7.1
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data as well as unauthorized update, insert or delete access to

CVE-2022-25760
accesslog Web
7.1
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible for an attacker to execute arbitrary JavaScript code on the host that this package is being run on.

CVE-2022-0821
orchardcms/orchardcore Web
7.1
HIGH
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVE-2022-2924
yetiforcecompany/yetiforcecrm Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

CVE-2022-1451
radareorg/radare2 Web
7.1
HIGH
EPSS
0.3%
2022 CWE-788 2 PoCs

Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

CVE-2022-0970
getgrav/grav Web
7.1
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVE-2022-35878
iota All-In-One Security Kit Web
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `ST` and `Location` HTTP response headers, as used within the `DoEnumUPnPService` action handler.

CVE-2022-20956
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.3%
2022 CWE-648 3 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vul

CVE-2022-0926
microweber/microweber Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0961
microweber/microweber Web
7.1
HIGH
EPSS
1.8%
2022 CWE-190 1 PoC

The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0253
livehelperchat/livehelperchat Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-41742
NGINX Web
7.1
HIGH
EPSS
0.1%
2022 CWE-787 1 PoC

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigge

CVE-2022-45365
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
20.1%
2022 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

CVE-2022-20822
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.5%
2022 CWE-22 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to. Cisco plans to release softw

CVE-2022-0378
microweber/microweber Web ⚡ nuclei
7.1
HIGH
EPSS
7.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-31192
DSpace Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2022-0956
star7th/showdoc Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

CVE-2022-0938
star7th/showdoc Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-32510
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.