3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-32172
zinc Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.

CVE-2022-0659
Sync QCloud COS Web Cloud Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-2386
Crowdsignal Dashboard – Polls, Surveys & more Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-28956
Software Genérico Web
N/A
UNKNOWN
EPSS
28.4%
2022 1 PoC

An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.

CVE-2022-2089
Bold Page Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-30780
Software Genérico Web
N/A
UNKNOWN
EPSS
81.5%
2022 3 PoCs

Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.

CVE-2022-28512
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

CVE-2022-2410
mTouch Quiz Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3141
Translate Multilingual sites – TranslatePress Web Database Windows
N/A
UNKNOWN
EPSS
3.9%
2022 CWE-89 4 PoCs

The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.

CVE-2022-1006
Advanced Booking Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

CVE-2022-46786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).

CVE-2022-2035
Rustici Software SCORM Engine Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.

CVE-2022-2362
Download Manager Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.

CVE-2022-1047
themify-ptb-search Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.

CVE-2022-32022
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

CVE-2022-28000
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.

CVE-2022-1577
Database Backup for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup schedule

CVE-2022-48612
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable places.

CVE-2022-25261
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.

CVE-2022-24223
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
27.5%
2022 1 PoC

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.