3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-25344
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly check parameters, sent in a /dvcset/sysset/set.cgi POST request via the arg01.Hostname field, before saving them on the server. In addition, the JavaScript malicious content is then reflected back to the end user and executed by the web browser.

CVE-2022-0782
Donations Web Database Windows
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-89 1 PoC

The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

CVE-2022-32250
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2022 13 PoCs

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

CVE-2022-24338
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.

CVE-2022-30887
Software Genérico Web
N/A
UNKNOWN
EPSS
5.2%
2022 3 PoCs

Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

CVE-2022-1977
Import Export All WordPress Images, Users & Post Types Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-918 1 PoC

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

CVE-2022-0397
WPC Smart Wishlist for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting

CVE-2022-0186
Image Photo Gallery Final Tiles Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

CVE-2022-2173
Advanced Database Cleaner Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting

CVE-2022-0199
Coming soon and Maintenance mode Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

CVE-2022-0817
BadgeOS Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.7%
2022 CWE-89 1 PoC

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-34534
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
28.9%
2022 0 PoCs

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

CVE-2022-4953
Elementor Website Builder Web Windows
N/A
UNKNOWN
EPSS
11.5%
2022 2 PoCs

The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.

CVE-2022-31403
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2022 1 PoC

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

CVE-2022-33980
Apache Commons Configuration Web
N/A
UNKNOWN
EPSS
86.7%
2022 7 PoCs

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (java

CVE-2022-0176
PowerPack Lite for Beaver Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0833
Church Admin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data

CVE-2022-29598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .

CVE-2022-35174
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.

CVE-2022-26585
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 1 PoC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.