1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-2072
Name Directory Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVE-2022-1690
Note Press Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

CVE-2022-0914
Export All URLs Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVE-2022-23911
Testimonial WordPress Plugin – AP Custom Testimonial Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

CVE-2022-36174
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.

CVE-2022-0662
AdRotate – Ad manager & AdSense Ads Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-0403
Library File Manager Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-434 1 PoC

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

CVE-2022-0592
MapSVG Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 1 PoC

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVE-2022-0212
SpiderCalendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-79 1 PoC

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

CVE-2022-1610
Seamless Donations: A Platform for Global Fundraising and Rebuilding using Stripe and PayPal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-0641
Popup Like box – Page Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-0989
NS WooCommerce Watermark Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-80 1 PoC

An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.

CVE-2022-0818
WooCommerce Affiliate Plugin – Coupon Affiliates Web Windows
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

CVE-2022-41184
SAP 3D Visual Enterprise Author Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-25812
Transposh WordPress Translation Web Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-94 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE

CVE-2022-0388
Interactive Medical Drawing of Human Body Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-2219
Unyson Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2022 CWE-79 1 PoC

The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-0444
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

CVE-2022-2133
OAuth Single Sign On – SSO (OAuth Client) Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-287 1 PoC

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

CVE-2022-1762
iQ Block Country Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.