13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-21631
JD Edwards EnterpriseOne Tools Web Database
6.1
MEDIUM
EPSS
2.2%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected are 9.2.6.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized up

CVE-2022-46350
SCALANCE X204RNA (HSR) Web
6.1
MEDIUM
EPSS
0.7%
2022 CWE-80 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. This can be used by an attacker to trigger a malicious request on the affected device.

CVE-2022-4369
WP-Lister Lite for Amazon Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin.

CVE-2022-22242
Junos OS Web Networking ⚡ nuclei
6.1
MEDIUM
EPSS
62.1%
2022 CWE-79 0 PoCs

A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21

CVE-2022-38167
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2022 1 PoC

The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS.

CVE-2022-0764
strapi/strapi Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-78 1 PoC

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

CVE-2022-21492
Business Intelligence Enterprise Edition Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks

CVE-2022-40841
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter.

CVE-2022-48111
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter.

CVE-2022-39799
SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) Web
6.1
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

CVE-2022-36433
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.

CVE-2022-23397
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2022 0 PoCs

The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."

CVE-2022-48012
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
4.6%
2022 0 PoCs

Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.

CVE-2022-21386
WebLogic Server DevOps Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized updat

CVE-2022-20657
Cisco Evolved Programmable Network Manager (EPNM) Web Networking
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco&nbsp;PI and Cisco&nbsp;EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browse

CVE-2022-2404
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-27926
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
94.1%
2022 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

CVE-2022-43263
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.

CVE-2022-45890
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).

CVE-2022-37307
Software Genérico Web
6.1
MEDIUM
EPSS
1.1%
2022 1 PoC

OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.