3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-21628
Java SE JDK and JRE Web Database
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java S

CVE-2022-24723
URI.js Web
5.3
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

CVE-2022-45027
Software Genérico Web
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.

CVE-2022-27631
DD-WRT Web
5.3
MEDIUM
EPSS
2.5%
2022 CWE-787 1 PoC

A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

CVE-2022-4057
Autoptimize Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
45.4%
2022 1 PoC

The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.

CVE-2022-4340
BookingPress Web Windows
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.

CVE-2022-4646
ikus060/rdiffweb Web
5.3
MEDIUM
EPSS
0.0%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.

CVE-2022-1563
wp-graphql-woocommerce Web Windows
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

CVE-2022-33161
Security Directory Server Web
5.3
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

CVE-2022-43980
Pandora FMS Web
5.2
MEDIUM
EPSS
0.3%
2022 CWE-352 2 PoCs

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.

CVE-2022-0157
phoronix-test-suite/phoronix-test-suite Web
5.2
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-50937
Ametys CMS Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in link text and descriptions to execute persistent attacks that compromise user sessions and manipulate application modules.

CVE-2022-50797
Stripe Green Downloads Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.

CVE-2022-50685
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVE-2022-50891
Owlfiles File Manager Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScript in users' browsers.

CVE-2022-50681
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers.

CVE-2022-50804
JF511-TV Web Networking
5.1
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.

CVE-2022-50802
ETAP Safety Manager Web
5.1
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials or performing unauthorized actions.

CVE-2022-4647
microweber/microweber Web
5.1
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-4979
Experience Platform Web Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.