3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0428
Content Egg Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2022-32277
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about the Squiz Matrix CMS product.

CVE-2022-2392
Lana Downloads Manager Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-552 1 PoC

The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

CVE-2022-35226
SAP Data Services Management Console Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console.

CVE-2022-28865
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

CVE-2022-35297
SAP Enable Now Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.

CVE-2022-34007
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2022 2 PoCs

EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.

CVE-2022-29296
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-24248
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2022 2 PoCs

RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to delete). Furthermore, an attacker might leverage the capability of arbitrary file deletion to circumvent certain web server security mechanisms such as deleting .htaccess file that would deactivate those security constraints.

CVE-2022-32310
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.

CVE-2022-2367
WSM Downloader Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-639 1 PoC

The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation

CVE-2022-25173
Jenkins Pipeline: Groovy Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-28924
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.

CVE-2022-34093
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.5%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.

CVE-2022-2050
WP-Paginate Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-28992
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

CVE-2022-26645
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2022 1 PoC

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

CVE-2022-31884
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.

CVE-2022-1600
YOP Poll Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

CVE-2022-0431
Insights from Google PageSpeed Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting