3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-26521
Software Genérico Web
N/A
UNKNOWN
EPSS
7.8%
2022 1 PoC

Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).

CVE-2022-23409
Software Genérico Web
N/A
UNKNOWN
EPSS
3.7%
2022 2 PoCs

The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.

CVE-2022-39809
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. Session hijacking or similar attacks would not be possible.

CVE-2022-1037
EXMAGE – WordPress Image Links Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-918 1 PoC

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVE-2022-22853
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Name field.

CVE-2022-2099
WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

CVE-2022-30050
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.

CVE-2022-0595
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVE-2022-2556
Mailchimp for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-918 1 PoC

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

CVE-2022-2278
Featured Image from URL (FIFU) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1255
Import and export users and customers Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

CVE-2022-24342
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

CVE-2022-33116
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitrary files via a directory traversal.

CVE-2022-36637
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter at /brand.php.

CVE-2022-36201
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 2 PoCs

Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.

CVE-2022-44010
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes the process. This does not require authentication. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

CVE-2022-1952
Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-434 1 PoC

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.

CVE-2022-0679
Narnoo Distributor Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2022 CWE-22 1 PoC

The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.

CVE-2022-31497
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.

CVE-2022-0252
GiveWP – Donation Plugin and Fundraising Platform Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting