3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3142
NEX-Forms – Ultimate Form Builder – Contact forms and much more Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2022 CWE-89 3 PoCs

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

CVE-2022-37190
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 0 PoCs

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

CVE-2022-2737
WP STAGING – Backup Duplicator & Migration Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-2537
WooCommerce PDF Invoices & Packing Slips Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

CVE-2022-29360
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.

CVE-2022-29939
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.

CVE-2022-35585
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parameter

CVE-2022-30280
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests lik

CVE-2022-32118
Software Genérico Web
N/A
UNKNOWN
EPSS
5.0%
2022 1 PoC

Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.

CVE-2022-0648
Team Circle Image Slider With Lightbox Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-30512
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.8%
2022 2 PoCs

School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.

CVE-2022-0448
CP Blocks Web Windows
N/A
UNKNOWN
EPSS
6.3%
2022 CWE-79 1 PoC

The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-36755
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

CVE-2022-0229
miniOrange's Google Authenticator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

CVE-2022-1392
Videos sync PDF Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2022 CWE-22 2 PoCs

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

CVE-2022-26101
Fiori Launchpad Web
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 2 PoCs

Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVE-2022-1960
MyCSS Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-32398
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

CVE-2022-31794
Software Genérico Web
N/A
UNKNOWN
EPSS
4.8%
2022 1 PoC

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.

CVE-2022-2083
Simple Single Sign On Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.