3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0857
McAfee ePolicy Orchestrator (ePO) Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.

CVE-2022-4756
My YouTube Channel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-22124
halo Web
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.

CVE-2022-4795
Galleries by Angie Makes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4714
WP Dark Mode Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-4717
Strong Testimonials Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4465
WP Video Lightbox Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-44944
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

CVE-2022-4464
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.

CVE-2022-4676
OSM Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-1755
SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

CVE-2022-36923
Software Genérico Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
32.5%
2022 0 PoCs

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

CVE-2022-43342
Software Genérico Web
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the KPI Title text field.

CVE-2022-30768
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

CVE-2022-21591
Transportation Management Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Ba

CVE-2022-1753
WoWonder Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-284 3 PoCs

A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.

CVE-2022-25849
joyqi/hyper-down Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

CVE-2022-4765
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4824
WP Blog and Widgets Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-0437
karma-runner/karma Web ⚡ nuclei
5.4
MEDIUM
EPSS
24.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.