3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-26644
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

CVE-2022-32409
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
66.5%
2022 1 PoC

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

CVE-2022-22968
Spring Framework Web
N/A
UNKNOWN
EPSS
20.5%
2022 1 PoC

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.

CVE-2022-28590
Software Genérico Web
N/A
UNKNOWN
EPSS
39.3%
2022 2 PoCs

A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.

CVE-2022-35174
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.

CVE-2022-29598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .

CVE-2022-0598
Login with phone number Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-27357
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-26585
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 1 PoC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

CVE-2022-1051
WPQA Builder Plugin Web Windows
N/A
UNKNOWN
EPSS
10.3%
2022 CWE-79 2 PoCs

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.

CVE-2022-23974
Apache Pinot Web
N/A
UNKNOWN
EPSS
3.2%
2022 CWE-674 1 PoC

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0

CVE-2022-1569
Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-30886
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.

CVE-2022-0440
Catch Themes Demo Import Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-434 1 PoC

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)

CVE-2022-29610
SAP NetWeaver Application Server ABAP Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

CVE-2022-1910
Shortcodes and extra features for Phlox theme Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2022 CWE-79 1 PoC

The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-2407
WP phpMyAdmin Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-35493
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 0 PoCs

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.

CVE-2022-0687
Amelia – Events & Appointments Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-434 1 PoC

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

CVE-2022-1938
Awin Data Feed Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings