3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1953
Product Configurator for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
3.9%
2022 CWE-22 1 PoC

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

CVE-2022-2092
WooCommerce PDF Invoices & Packing Slips Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.

CVE-2022-1762
iQ Block Country Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

CVE-2022-32028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

CVE-2022-2340
W-DALIL Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 2 PoCs

The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-32007
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.

CVE-2022-35227
SAP NetWeaver Enterprise Portal (WPC) Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the attacker to execute arbitrary script code which could lead to stealing or modifying of authentication information of the user, such as data relating to his or her current session.

CVE-2022-36736
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed by the vendor

CVE-2022-1830
Amazon Einzeltitellinks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-0784
Title Experiments Free Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.9%
2022 CWE-89 1 PoC

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-26271
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.7%
2022 0 PoCs

74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

CVE-2022-34619
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.

CVE-2022-1539
Exports and Reports Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-1236 1 PoC

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

CVE-2022-0271
LearnPress – WordPress LMS Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 CWE-79 1 PoC

The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting

CVE-2022-29004
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
39.7%
2022 1 PoC

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVE-2022-0765
Loco Translate Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

CVE-2022-1088
Page Security & Membership Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-0887
Easy Social Icons Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

CVE-2022-46907
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
3.2%
2022 CWE-79 1 PoC

A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.

CVE-2022-1896
underConstruction Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.