3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3125
Frontend File Manager Plugin Web Windows
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-434 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

CVE-2022-0142
Visual Form Builder Web Windows
N/A
UNKNOWN
EPSS
4.7%
2022 CWE-1236 1 PoC

The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVE-2022-28962
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.

CVE-2022-24263
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.9%
2022 3 PoCs

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

CVE-2022-2423
DW Promobar Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-24288
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2022 CWE-78 0 PoCs

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

CVE-2022-0447
Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting

CVE-2022-1690
Note Press Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

CVE-2022-1990
Nested Pages Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVE-2022-32403
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4

CVE-2022-2567
Form Builder CP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-32532
Apache Shiro DevOps Web
N/A
UNKNOWN
EPSS
80.9%
2022 CWE-863 3 PoCs

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVE-2022-26589
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.

CVE-2022-22734
Simple Quotation Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could make a logged in admin create or edit arbitrary quote, and put Cross-Site Scripting payloads in them

CVE-2022-0212
SpiderCalendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-79 1 PoC

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

CVE-2022-1221
Gwyn's Imagemap Selector Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-79 1 PoC

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

CVE-2022-0279
AnyComment Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-362 1 PoC

The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users

CVE-2022-31400
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

CVE-2022-30040
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.

CVE-2022-37175
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.