3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-28033
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
58.4%
2022 0 PoCs

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

CVE-2022-25174
Jenkins Pipeline: Shared Groovy Libraries Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-1765
Hot Linked Image Cacher Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).

CVE-2022-34048
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 0 PoCs

Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.

CVE-2022-1791
One Click Plugin Updater Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.

CVE-2022-1202
WP-CRM – Customer Relations Management for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-1236 1 PoC

The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.

CVE-2022-2369
YaySMTP – Simple WP SMTP Mail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-862 1 PoC

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

CVE-2022-0760
Simple Link Directory Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.3%
2022 CWE-89 1 PoC

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-1885
Cimy Header Image Rotator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-1472
Better Find and Replace Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

CVE-2022-27984
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-28533
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.

CVE-2022-35589
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parameter.

CVE-2022-2374
Simply Schedule Appointments – WordPress Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-26479
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

CVE-2022-37063
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

CVE-2022-24961
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

CVE-2022-2411
Auto More Tag Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-26265
Software Genérico Web
N/A
UNKNOWN
EPSS
71.5%
2022 3 PoCs

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

CVE-2022-26521
Software Genérico Web
N/A
UNKNOWN
EPSS
7.8%
2022 1 PoC

Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).