3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-24646
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

CVE-2022-1168
WP JobSearch Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2022 CWE-79 1 PoC

There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

CVE-2022-23988
WS Form LITE – Drag & Drop Contact Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
14.4%
2022 CWE-79 1 PoC

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

CVE-2022-2559
Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users

CVE-2022-31498
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.

CVE-2022-2260
GiveWP – Donation Plugin and Fundraising Platform DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.

CVE-2022-31876
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.

CVE-2022-0404
Material Design for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

CVE-2022-48197
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.7%
2022 2 PoCs

Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2022-0876
Social comments by WpDevArt Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-37207
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

CVE-2022-0693
Master Elements Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2022 CWE-89 1 PoC

The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

CVE-2022-3207
Simple File List Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0781
Nirweb support Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.9%
2022 CWE-89 1 PoC

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

CVE-2022-28006
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.

CVE-2022-0478
Event Manager and Tickets Selling Plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

CVE-2022-1275
BannerMan Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite)

CVE-2022-0633
UpdraftPlus WordPress Backup Plugin (Free) Web Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-863 2 PoCs

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

CVE-2022-0163
Smart Forms – when you need more than just a contact form Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-862 1 PoC

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.

CVE-2022-23048
Exponent CMS Web
N/A
UNKNOWN
EPSS
4.6%
2022 2 PoCs

Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.