3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0948
Order Listener for WooCommerce – Play Sounds Instantly on New Orders Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 1 PoC

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

CVE-2022-0398
ThirstyAffiliates Affiliate Link Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

CVE-2022-25175
Jenkins Pipeline: Multibranch Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-1268
Donate Extra Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting

CVE-2022-25062
Software Genérico Web
N/A
UNKNOWN
EPSS
29.0%
2022 1 PoC

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVE-2022-29940
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.

CVE-2022-2041
Brizy – Page Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-0640
Pricing Table Builder – AP Pricing Tables Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-26632
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.

CVE-2022-32400
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

CVE-2022-26635
Software Genérico Web
N/A
UNKNOWN
EPSS
8.2%
2022 1 PoC

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

CVE-2022-36202
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.

CVE-2022-0399
Advanced Product Labels for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting

CVE-2022-25094
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.

CVE-2022-1334
WP YouTube Live Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-31454
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books has a relationship to Yii 2.

CVE-2022-1779
Auto Delete Posts Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

CVE-2022-48149
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVE-2022-31415
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.

CVE-2022-25228
CandidATS Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=joborders&a=show' via the 'jobOrderID' and '/index.php?m=companies&a=show' via the 'companyID' parameter