3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-45836
Download Manager Web ⚡ nuclei
7.1
HIGH
EPSS
8.0%
2022 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

CVE-2022-20956
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.3%
2022 CWE-648 3 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vul

CVE-2022-32510
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-50894
VIAVIWEB Wallpaper Admin Web Database
7.1
HIGH
EPSS
0.0%
2022 CWE-89 1 PoC

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

CVE-2022-21544
FLEXCUBE Universal Banking Web Database
7.1
HIGH
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availabi

CVE-2022-0938
star7th/showdoc Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-37318
Software Genérico Web
7.0
HIGH
EPSS
0.6%
2022 1 PoC

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2022-1340
yetiforcecompany/yetiforcecrm Web
7.0
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-3274
ikus060/rdiffweb Web
7.0
HIGH
EPSS
0.7%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.

CVE-2022-41741
NGINX Web
7.0
HIGH
EPSS
0.8%
2022 CWE-787 1 PoC

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger proces

CVE-2022-50956
amministrazione-aperta Web Windows
6.9
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server.

CVE-2022-2589
beancount/fava Web
6.9
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.

CVE-2022-0967
star7th/showdoc Web
6.9
MEDIUM
EPSS
0.8%
2022 CWE-79 2 PoCs

Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0893
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-4512
Better Font Awesome Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4471
YARPP Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-0020
Cortex XSOAR Web Networking
6.8
MEDIUM
EPSS
1.0%
2022 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

CVE-2022-46368
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2022-46367
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.