1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-2460
WPDating Web Database Windows
4.3
MEDIUM
EPSS
4.4%
2022 1 PoC

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

CVE-2022-3151
WP Custom Cursors Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

CVE-2022-2912
Craw Data Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 CWE-918 1 PoC

The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

CVE-2022-28790
Link to Windows Service Windows
4.0
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

CVE-2022-3258
Workforce Access Windows
3.7
LOW
EPSS
0.2%
2022 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.

CVE-2022-3343
WPQA Builder Web Windows
3.5
LOW
EPSS
0.3%
2022 1 PoC

The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.

CVE-2022-28766
Zoom Client for Meetings for Windows (32-bit) Windows
3.3
LOW
EPSS
0.4%
2022 CWE-94 1 PoC

Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.

CVE-2022-28764
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Database Windows
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

CVE-2022-4102
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) Web Windows
3.1
LOW
EPSS
0.1%
2022 1 PoC

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.

CVE-2022-4309
Subscribe2 Web Windows
3.1
LOW
EPSS
0.1%
2022 1 PoC

The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.

CVE-2022-4109
Wholesale Market for WooCommerce Web Windows
2.7
LOW
EPSS
0.3%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

CVE-2022-0590
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0193
Complianz – GDPR/CCPA Cookie Consent Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 2 PoCs

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-25810
Transposh WordPress Translation Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-862 1 PoC

The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileged user. Basically all Utilities functionalities are vulnerable this way, which involves resetting configurations and backup/restore operations.

CVE-2022-0214
Popup | Custom Popup Builder Web Windows
N/A
UNKNOWN
EPSS
2.0%
2022 1 PoC

The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

CVE-2022-2168
Download Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 CWE-79 1 PoC

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-2763
WP Socializer – Simple & Easy Social Media Share Icons Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1556
StaffList Web Database Windows
N/A
UNKNOWN
EPSS
8.8%
2022 CWE-89 2 PoCs

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

CVE-2022-3209
soledad Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-1599
Admin Management Xtended Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.