3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-22976
Spring Security Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-190 2 PoCs

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVE-2022-1643
Birthdays Widget Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVE-2022-37892
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; Web
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3

CVE-2022-0879
Caldera Forms – More Than Contact Forms Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-32015
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.

CVE-2022-1532
Themify – WooCommerce Product Filter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-33910
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute.

CVE-2022-1913
Add Post URL Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-27671
SAP BusinessObjects Business Intelligence Platform Web
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-201 1 PoC

A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.

CVE-2022-22545
SAP NetWeaver Application Server ABAP and ABAP Platform Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-200 1 PoC

A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.

CVE-2022-0147
Cookie Information | Free GDPR Consent Solution Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2022 CWE-79 1 PoC

The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVE-2022-22980
Spring Data MongoDB Web Database
N/A
UNKNOWN
EPSS
83.2%
2022 5 PoCs

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

CVE-2022-32430
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.9%
2022 0 PoCs

An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

CVE-2022-41725
mime/multipart Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing "up to maxMemory bytes +10MB (reserved for non-file parts) in memory". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurab

CVE-2022-0814
Ubigeo de Perú para Woocommerce y WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
58.2%
2022 CWE-89 1 PoC

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

CVE-2022-24344
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

CVE-2022-1844
WP Sentry Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVE-2022-1604
MailerLite – Signup forms (official) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-1512
ScrollReveal.js Effects Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 2 PoCs

The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-2341
Simple Page Transition Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 2 PoCs

The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)