3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1165
Blackhole for Bad Bots Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-639 1 PoC

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.

CVE-2022-36639
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2022-39818
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2022 1 PoC

In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

CVE-2022-1827
PDF24 Article To PDF Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-1435
WPCargo Track & Trace DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-0230
Better WordPress Google XML Sitemaps (support Sitemap Index, Multi-site and Google News) Web Windows
N/A
UNKNOWN
EPSS
14.8%
2022 CWE-79 1 PoC

The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins

CVE-2022-2635
Autoptimize Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0684
WP Home Page Menu Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1995
Malware Scanner Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

CVE-2022-25003
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.

CVE-2022-25762
Apache Tomcat Web
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-404 1 PoC

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVE-2022-36667
Software Genérico Web
N/A
UNKNOWN
EPSS
3.7%
2022 1 PoC

Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.

CVE-2022-1216
Advanced Image Sitemap Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.

CVE-2022-25497
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

CVE-2022-1171
Vertical scroll recent post Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2022-2557
Team – WordPress Team Members Showcase Plugin Web Windows
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-22 1 PoC

The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

CVE-2022-27982
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2022 1 PoC

RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php.

CVE-2022-25487
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2022 1 PoC

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

CVE-2022-1710
Appointment Hour Booking – WordPress Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-32311
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.