3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0674
Kunze Law Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1614
WP-EMail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.

CVE-2022-31977
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.1%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVE-2022-1914
Clean-Contact Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well

CVE-2022-32024
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

CVE-2022-24992
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2022 4 PoCs

A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.

CVE-2022-1112
Autolinks Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-79 1 PoC

The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack

CVE-2022-1788
Change Uploaded File Permissions Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

CVE-2022-1691
Realty Workstation Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-89 2 PoCs

The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection

CVE-2022-31301
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.

CVE-2022-2151
Best Contact Management Software for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-30557
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.

CVE-2022-2267
Mailchimp for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-918 1 PoC

The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

CVE-2022-1956
Shortcut Macros Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them.

CVE-2022-1152
Menubar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in the response via the menubar AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting

CVE-2022-32094
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.8%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.

CVE-2022-35195
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php

CVE-2022-2172
LinkWorth Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.

CVE-2022-0164
Coming soon and Maintenance mode Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

CVE-2022-29650
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.