3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-29004
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
39.7%
2022 1 PoC

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVE-2022-0765
Loco Translate Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

CVE-2022-1088
Page Security & Membership Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-0887
Easy Social Icons Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

CVE-2022-46907
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
3.2%
2022 CWE-79 1 PoC

A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.

CVE-2022-1896
underConstruction Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.

CVE-2022-31663
VMware Workspace ONE Access, Identity Manager and vRealize Automation Web
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.

CVE-2022-24637
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2022 11 PoCs

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

CVE-2022-34047
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
59.2%
2022 3 PoCs

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].

CVE-2022-25089
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
43.2%
2022 3 PoCs

Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.

CVE-2022-31382
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

CVE-2022-30777
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2022 1 PoC

Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.

CVE-2022-40621
WN531G3 Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-294 1 PoC

Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

CVE-2022-1456
Poll Maker Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

CVE-2022-1776
Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-0787
Limit Login Attempts (Spam Protection) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
47.3%
2022 CWE-89 1 PoC

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

CVE-2022-31813
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-348 1 PoC

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

CVE-2022-1063
Thank Me Later Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputting it in the Messages list, which could allow high privileges users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-31398
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

CVE-2022-31325
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 3 PoCs

There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.