3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0493
String locator Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-22 1 PoC

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

CVE-2022-1801
Very Simple Contact Form Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-804 1 PoC

The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.

CVE-2022-28997
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

CVE-2022-2072
Name Directory Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVE-2022-38796
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.

CVE-2022-23046
PhpIPAM Web Database
N/A
UNKNOWN
EPSS
49.0%
2022 5 PoCs

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

CVE-2022-29005
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2022 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVE-2022-1166
Noo JobMonster Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-22 1 PoC

The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.

CVE-2022-1846
Tiny Contact Form Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-30776
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
45.5%
2022 2 PoCs

atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.

CVE-2022-0720
Amelia – Events & Appointments Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-863 1 PoC

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

CVE-2022-31876
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.

CVE-2022-27413
Software Genérico Web Database
N/A
UNKNOWN
EPSS
12.0%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.

CVE-2022-27432
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

CVE-2022-28479
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

CVE-2022-25344
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly check parameters, sent in a /dvcset/sysset/set.cgi POST request via the arg01.Hostname field, before saving them on the server. In addition, the JavaScript malicious content is then reflected back to the end user and executed by the web browser.

CVE-2022-0782
Donations Web Database Windows
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-89 1 PoC

The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

CVE-2022-32250
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2022 13 PoCs

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

CVE-2022-24338
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.