3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1265
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-1964
Easy SVG Support Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVE-2022-0899
Header Footer Code Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2022 CWE-79 1 PoC

The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-22533
SAP NetWeaver Application Server Java Web
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-416 1 PoC

Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in system shutdown rendering the system unavailable.

CVE-2022-4466
WordPress Infinite Scroll Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-25581
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

CVE-2022-26624
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.

CVE-2022-0828
Download Manager Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

CVE-2022-32274
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function.

CVE-2022-1792
Quick Subscribe Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them

CVE-2022-26263
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2022 0 PoCs

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

CVE-2022-1164
WYZI Business Finder Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature

CVE-2022-23943
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
60.6%
2022 CWE-787 1 PoC

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

CVE-2022-40714
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.

CVE-2022-35294
SAP NetWeaver AS ABAP Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.

CVE-2022-0446
Simple Banner Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-28364
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.

CVE-2022-31798
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.6%
2022 3 PoCs

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-1220
FoxyShop Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-1424
Ask me Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.