3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-28364
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.

CVE-2022-2395
weForms – Easy Drag & Drop Contact Form Builder For WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-1265
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-31798
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.6%
2022 3 PoCs

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-1220
FoxyShop Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-1964
Easy SVG Support Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVE-2022-1424
Ask me Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

CVE-2022-2981
Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-552 1 PoC

The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

CVE-2022-2239
Request a Quote Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0694
Advanced Booking Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVE-2022-4782
ClickFunnels Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-1123
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-89 1 PoC

The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.

CVE-2022-0873
Gmedia Photo Gallery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-79 1 PoC

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

CVE-2022-31861
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

CVE-2022-32393
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4

CVE-2022-23896
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).

CVE-2022-0214
Popup | Custom Popup Builder Web Windows
N/A
UNKNOWN
EPSS
2.0%
2022 1 PoC

The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

CVE-2022-29158
Apache OFBiz Web
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-1333 1 PoC

Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599

CVE-2022-2410
mTouch Quiz Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4115
Editorial Calendar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users.