13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-45028
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request sent to /cgi-bin/logs.ha.

CVE-2022-47052
Software Genérico Web Networking
6.1
MEDIUM
EPSS
1.4%
2022 1 PoC

The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerability using a specially crafted URL. This affects firmware versions: V1.1.0.112_1.0.1, V1.1.0.114_1.0.1.

CVE-2022-31469
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.

CVE-2022-21361
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access

CVE-2022-45728
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2022-21453
WebLogic Server Web Database
6.1
MEDIUM
EPSS
1.1%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update,

CVE-2022-37309
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.

CVE-2022-2669
WP Taxonomy Import Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-3484
wpb-show-core Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.5%
2022 CWE-79 1 PoC

The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-28354
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.

CVE-2022-43332
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

CVE-2022-42746
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
3.0%
2022 0 PoCs

CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-42071
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.

CVE-2022-42118
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
13.2%
2022 1 PoC

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.

CVE-2022-21257
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to

CVE-2022-46073
Software Genérico DevOps Web ⚡ nuclei
6.1
MEDIUM
EPSS
29.5%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-3415
Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back Web Windows
6.1
MEDIUM
EPSS
1.1%
2022 CWE-79 1 PoC

The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message

CVE-2022-40359
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
9.2%
2022 1 PoC

Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.

CVE-2022-39181
Reports plugin for GLPI Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or emailed directly to the victim. URLs constructed in this manner

CVE-2022-4453
3D FlipBook Web Windows
6.1
MEDIUM
EPSS
0.4%
2022 1 PoC

The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.