3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1994
Login With OTP Over SMS, Email, WhatsApp and Google Authenticator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2022-0364
Modern Events Calendar Lite Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-2133
OAuth Single Sign On – SSO (OAuth Client) Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-287 1 PoC

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

CVE-2022-1647
FormCraft – Contact Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-25373
Software Genérico Web
N/A
UNKNOWN
EPSS
13.3%
2022 1 PoC

Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

CVE-2022-0700
Simple Tracking Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1576
WP Maintenance Mode & Coming Soon Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2022-0403
Library File Manager Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-434 1 PoC

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

CVE-2022-28771
SAP Business One License service API Web
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-306 1 PoC

Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.

CVE-2022-0958
Mark Posts Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3208
Simple File List Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.

CVE-2022-34963
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2022 2 PoCs

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.

CVE-2022-30016
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.

CVE-2022-2376
Directorist – WordPress Business Directory Plugin with Classified Ads Listings Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.5%
2022 CWE-862 1 PoC

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

CVE-2022-1422
Discy Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

CVE-2022-32195
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2022 0 PoCs

Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

CVE-2022-26588
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.

CVE-2022-1465
WPC Smart Wishlist for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

CVE-2022-46080
Software Genérico Web
N/A
UNKNOWN
EPSS
15.2%
2022 3 PoCs

Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

CVE-2022-24004
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2022 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticated user to inject arbitrary code into the messenger title (aka new_title) field when editing an existing conversation. The payload executes in the browser of any conversation participant with the sidebar shown.