3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-38357
Eyes of Network Web Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the url parameter of /module/module_frame/index.php.

CVE-2022-1167
Careerup Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.

CVE-2022-1847
Rotating Posts Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-0874
WP Social Buttons Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-25004
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.

CVE-2022-39810
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.

CVE-2022-0863
WP SVG Icons Web Windows
N/A
UNKNOWN
EPSS
13.3%
2022 CWE-434 1 PoC

The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.

CVE-2022-1192
Turn off all comments Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 2 PoCs

The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0728
Easy Smooth Scroll Links Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1203
Content Mask Web Windows
N/A
UNKNOWN
EPSS
4.5%
2022 2 PoCs

The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options

CVE-2022-1757
pagebar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues

CVE-2022-26633
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.

CVE-2022-0328
Simple Membership Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2022-0830
FormBuilder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.

CVE-2022-24646
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

CVE-2022-1168
WP JobSearch Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2022 CWE-79 1 PoC

There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

CVE-2022-23988
WS Form LITE – Drag & Drop Contact Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
14.4%
2022 CWE-79 1 PoC

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

CVE-2022-2559
Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users

CVE-2022-31498
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.

CVE-2022-2260
GiveWP – Donation Plugin and Fundraising Platform DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.