3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0814
Ubigeo de Perú para Woocommerce y WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
58.2%
2022 CWE-89 1 PoC

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

CVE-2022-24344
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

CVE-2022-1844
WP Sentry Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVE-2022-1604
MailerLite – Signup forms (official) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-1512
ScrollReveal.js Effects Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 2 PoCs

The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-2341
Simple Page Transition Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 2 PoCs

The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1391
Cab fare calculator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.7%
2022 CWE-22 2 PoCs

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

CVE-2022-0601
Countdown, Coming Soon, Maintenance – Countdown & Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-27351
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2022 2 PoCs

Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-29615
SAP NetWeaver Developer Studio (NWDS) Web
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-502 1 PoC

SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.

CVE-2022-1712
LiveSync for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-0169
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.2%
2022 CWE-89 2 PoCs

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVE-2022-0681
Simple Membership Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

CVE-2022-2090
Discount Rules for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting

CVE-2022-0642
JivoChat Live Chat – WP live chat plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

CVE-2022-31296
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.3%
2022 2 PoCs

Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.

CVE-2022-2370
YaySMTP Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them

CVE-2022-1327
Image Gallery – Grid Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-35172
SAP NetWeaver Enterprise Portal Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-0287
myCred Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog