3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-22125
halo Web
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.

CVE-2022-4260
WP-Ban Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
1.0%
2022 1 PoC

The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-32769
AVideo Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Playlists plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's playlists.

CVE-2022-40711
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users.

CVE-2022-3919
Jetpack CRM Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3855
404 to Start Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3837
Uji Countdown Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Uji Countdown WordPress plugin before 2.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3466
Red Hat OpenShift Container Platform 4.12 DevOps Web
4.8
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

CVE-2022-21402
Communications Operations Monitor Web Database
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability c

CVE-2022-3601
Image Hover Effects Css3 Web Cloud Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3350
Contact Bank – Contact Form Builder for WordPress Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-40028
Software Genérico Web
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullName parameter.

CVE-2022-3610
Jeeng Push Notifications Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-23179
Contact Form & Lead Form Elementor Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3909
Add Comments Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-42096
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
21.4%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

CVE-2022-4226
Simple Basic Contact Form Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3074
Slider Hero with Animation, Video Background Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

CVE-2022-3832
External Media Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3070
Generate PDF using Contact Form 7 Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.