3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-29732
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-0422
White Label CMS Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

CVE-2022-1684
CUBE SLIDER Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin

CVE-2022-31795
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2022 1 PoC

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.

CVE-2022-23126
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.

CVE-2022-25811
Transposh WordPress Translation Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-89 1 PoC

The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection

CVE-2022-30126
Apache Tika Web
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

CVE-2022-0254
WordPress Zero Spam Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

CVE-2022-22852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.

CVE-2022-0620
Delete Old Orders Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-24595
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2022 1 PoC

Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Control in usr/bin/afb-daemon. To exploit the vulnerability, an attacker should send a well-crafted HTTP (or WebSocket) request to the socket listened by the afb-daemon process. No credentials nor user interactions are required.

CVE-2022-0410
WP Visitor Statistics (Real Time Traffic) Web Database Windows
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-89 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection

CVE-2022-1781
postTabs Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-2575
WBW Currency Switcher for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1092
myCred Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

CVE-2022-28867
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.

CVE-2022-1156
Books & Papers Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-31856
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.

CVE-2022-26158
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

CVE-2022-28955
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2022 1 PoC

An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.