3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4672
WordPress Simple Shopping Cart Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4828
Bold Timeline Lite Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4551
Rich Table of Contents Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-42099
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.

CVE-2022-43144
Software Genérico Web
5.4
MEDIUM
EPSS
2.0%
2022 3 PoCs

A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-21396
Communications Operations Monitor Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2022-4482
Carousel, Slider, Gallery by WP Carousel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4570
Top 10 Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Top 10 WordPress plugin before 3.2.3 does not validate and escape some of its Block attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-39172
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated, low-privileged attacker to execute arbitrary code in the victim's browser via name field of a process.

CVE-2022-35137
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

CVE-2022-39420
Transportation Management Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Functional Security). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base S

CVE-2022-0196
phoronix-test-suite/phoronix-test-suite Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-4394
iPages Flipbook For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-4658
RSSImport Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-3933
Essential Real Estate Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
5.5%
2022 1 PoC

The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.

CVE-2022-42954
Software Genérico Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Keyfactor EJBCA before 7.10.0 allows XSS.

CVE-2022-4677
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44946
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

CVE-2022-25849
joyqi/hyper-down Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

CVE-2022-4835
Social Sharing Toolkit Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.