3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1800
Export any WordPress data to XML/CSV Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

CVE-2022-28959
Software Genérico Web
N/A
UNKNOWN
EPSS
3.0%
2022 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

CVE-2022-37253
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter

CVE-2022-24264
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
23.7%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

CVE-2022-26251
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

CVE-2022-43710
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site request forgery (CSRF) because the unique token could be deduced using the names of all input fields.

CVE-2022-1630
WP-EMail Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack

CVE-2022-26156
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form action. Form-action hijacking vulnerabilities arise when an application places user-supplied input into the action URL of an HTML form. An attacker can use this vulnerability to construct a URL that, if visited by another application user, will modify the action URL of a form to point to the attacker's server.

CVE-2022-27346
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2022 2 PoCs

Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-1398
External Media without Import Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
40.5%
2022 CWE-918 1 PoC

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

CVE-2022-39190
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.

CVE-2022-32444
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2022 0 PoCs

An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.

CVE-2022-1625
New User Approve Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.

CVE-2022-23045
PhpIPAM Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.

CVE-2022-25022
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2022 3 PoCs

A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

CVE-2022-1506
WP BORN BABIES PLUGIN Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVE-2022-2799
Affiliates Manager Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-27412
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.

CVE-2022-32397
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4

CVE-2022-0948
Order Listener for WooCommerce – Play Sounds Instantly on New Orders Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 1 PoC

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection