3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-29014
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2022 2 PoCs

A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

CVE-2022-28997
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

CVE-2022-1170
Noo JobMonster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-79 1 PoC

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

CVE-2022-2072
Name Directory Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVE-2022-1685
Five Minute Webshop Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection

CVE-2022-2118
404s Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-1089
Bulk Edit and Create User Profiles – WP Sheet Editor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-32402
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4

CVE-2022-1394
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-35298
SAP NetWeaver Enterprise Portal (KMC) Web
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser session.

CVE-2022-0592
MapSVG Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 1 PoC

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVE-2022-1994
Login With OTP Over SMS, Email, WhatsApp and Google Authenticator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2022-2133
OAuth Single Sign On – SSO (OAuth Client) Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-287 1 PoC

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

CVE-2022-1647
FormCraft – Contact Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-25373
Software Genérico Web
N/A
UNKNOWN
EPSS
13.3%
2022 1 PoC

Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

CVE-2022-0700
Simple Tracking Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1576
WP Maintenance Mode & Coming Soon Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2022-0403
Library File Manager Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-434 1 PoC

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

CVE-2022-28771
SAP Business One License service API Web
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-306 1 PoC

Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.

CVE-2022-0958
Mark Posts Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed