3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-26613
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.

CVE-2022-1692
CP Image Store with Slideshow Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 2 PoCs

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

CVE-2022-24127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into the project title (app_title) field when editing an existing project. The payload is then reflected within the title tag of the page.

CVE-2022-26159
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 2 PoCs

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

CVE-2022-35115
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.

CVE-2022-1842
OpenBook Book Data Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVE-2022-0208
MapPress Maps for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 CWE-79 1 PoC

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

CVE-2022-23321
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0.

CVE-2022-32429
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 4 PoCs

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.

CVE-2022-2144
Jquery Validation For Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack

CVE-2022-0745
Like Button Rating ♥ LikeBtn Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-862 1 PoC

The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body