3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-41445
Software Genérico Web
4.8
MEDIUM
EPSS
1.6%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.

CVE-2022-42094
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
38.0%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

CVE-2022-4199
Link Library Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4196
Multi Step Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-32768
AVideo Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's streams.

CVE-2022-0209
Mitsol Social Post Feed Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3237
WP Contact Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-45224
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.

CVE-2022-3811
EU Cookie Law for GDPR/CCPA Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-30628
Supersmart.me – Walk Through Web
4.8
MEDIUM
EPSS
0.0%
2022 3 PoCs

It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX

CVE-2022-44213
Software Genérico Web Cloud
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-2563
Tutor LMS – eLearning and online course solution Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-40490
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

CVE-2022-3829
Font Awesome 4 Menus Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4119
Image Optimizer, Resizer and CDN Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4010
Image Hover Effects Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3838
WPUpper Share Buttons Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-40846
Software Genérico Web Networking
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.

CVE-2022-20967
Cisco Identity Services Engine Software Web Networking
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTM

CVE-2022-3441
Rock Convert Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)