3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-34093
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.5%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.

CVE-2022-2050
WP-Paginate Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-28992
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

CVE-2022-23911
Testimonial WordPress Plugin – AP Custom Testimonial Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

CVE-2022-26645
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2022 1 PoC

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

CVE-2022-31884
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.

CVE-2022-1600
YOP Poll Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

CVE-2022-0431
Insights from Google PageSpeed Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-1558
Curtain Web Windows
N/A
UNKNOWN
EPSS
2.4%
2022 CWE-79 2 PoCs

The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVE-2022-34966
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.

CVE-2022-0739
BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin Web Database Windows
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 10 PoCs

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

CVE-2022-36636
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.

CVE-2022-1889
Newsletter – Send awesome emails from WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

CVE-2022-30518
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.

CVE-2022-2276
WP Edit Menu Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog

CVE-2022-40778
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to execute arbitrary JavaScript or HTML because of the blocked page response.

CVE-2022-23907
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

CVE-2022-32394
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3

CVE-2022-2638
Export All URLs Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-73 1 PoC

The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server

CVE-2022-23366
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 3 PoCs

HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.