3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4763
Icon Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-25849
joyqi/hyper-down Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

CVE-2022-4670
PDF.js Viewer Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The PDF.js Viewer WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-0576
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.

CVE-2022-4667
RSS Aggregator by Feedzy Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-39834
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2022 1 PoC

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.

CVE-2022-25303
whoogle-search Web
5.4
MEDIUM
EPSS
0.3%
2022 3 PoCs

The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the [flask.render_template](https://flask.palletsprojects.com/en/2.1.x/api/flask.render_template) function. However, the error_message is rendered using the [| safe filter](https://jinja.palletsprojects.com/en/3.1.x/templates/working-with-automatic-escaping), meaning the user input is not escaped.

CVE-2022-0323
bobthecow/mustache.php Web
5.3
MEDIUM
EPSS
0.2%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

CVE-2022-24723
URI.js Web
5.3
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

CVE-2022-28665
FreshTomato Web
5.3
MEDIUM
EPSS
4.0%
2022 CWE-787 1 PoC

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable URL-decoding feature that can lead to memory corruption.

CVE-2022-40482
Software Genérico Web
5.3
MEDIUM
EPSS
0.5%
2022 1 PoC

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

CVE-2022-40691
SDS-3008 Series Industrial Ethernet Switch Web
5.3
MEDIUM
EPSS
1.3%
2022 CWE-200 2 PoCs

An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-4417
WP Cerber Security, Anti-spam & Malware Scan Web Windows
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users

CVE-2022-41697
Ghost Web ⚡ nuclei
5.3
MEDIUM
EPSS
18.6%
2022 CWE-204 1 PoC

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2022-31062
glpi-inventory-plugin Web
5.3
MEDIUM
EPSS
11.0%
2022 CWE-22 1 PoC

### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

CVE-2022-4097
All-In-One Security (AIOS) Web Windows
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

CVE-2022-39862
Samsung Mobile Devices Web
5.3
MEDIUM
EPSS
0.3%
2022 CWE-285 1 PoC

Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.

CVE-2022-0394
livehelperchat/livehelperchat Web
5.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

CVE-2022-2462
Transposh WordPress Translation Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
5.5%
2022 CWE-200 1 PoC

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.

CVE-2022-26376
Asuswrt-Merlin New Gen Web
5.3
MEDIUM
EPSS
0.7%
2022 CWE-787 1 PoC

A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.