3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-31403
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2022 1 PoC

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

CVE-2022-33980
Apache Commons Configuration Web
N/A
UNKNOWN
EPSS
86.7%
2022 7 PoCs

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (java

CVE-2022-0176
PowerPack Lite for Beaver Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0833
Church Admin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data

CVE-2022-29598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .

CVE-2022-35174
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.

CVE-2022-26585
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 1 PoC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

CVE-2022-0594
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
44.0%
2022 CWE-863 1 PoC

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

CVE-2022-25018
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2022 2 PoCs

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

CVE-2022-0320
Essential Addons for Elementor Web Windows
N/A
UNKNOWN
EPSS
4.5%
2022 CWE-22 2 PoCs

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

CVE-2022-23074
recipes Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.

CVE-2022-24977
Software Genérico Web
N/A
UNKNOWN
EPSS
28.1%
2022 1 PoC

ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.

CVE-2022-34962
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2022 2 PoCs

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.

CVE-2022-1395
Easy FAQ with Expanding Text Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-1763
Static Page eXtended Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

CVE-2022-1843
MailPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

CVE-2022-1269
Fast Flow Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2022-1322
Coming Soon – Under Construction Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-28397
Software Genérico Web
N/A
UNKNOWN
EPSS
4.0%
2022 2 PoCs

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional

CVE-2022-0779
User Meta – User Profile Builder and User management plugin Web Windows
N/A
UNKNOWN
EPSS
13.7%
2022 CWE-22 1 PoC

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads