1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-0279
AnyComment Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-362 1 PoC

The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users

CVE-2022-1772
Google Places Reviews Web Windows
N/A
UNKNOWN
EPSS
2.5%
2022 CWE-79 1 PoC

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVE-2022-24644
Software Genérico Windows
N/A
UNKNOWN
EPSS
10.8%
2022 3 PoCs

ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.

CVE-2022-0784
Title Experiments Free Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.9%
2022 CWE-89 1 PoC

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-2314
VR Calendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2022 CWE-78 1 PoC

The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

CVE-2022-0765
Loco Translate Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

CVE-2022-1971
NextCellent Gallery – NextGEN Legacy Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0431
Insights from Google PageSpeed Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-24372
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

CVE-2022-0825
Amelia – Events & Appointments Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-863 1 PoC

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

CVE-2022-1672
Insights from Google PageSpeed Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

CVE-2022-0255
Database Backup for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue

CVE-2022-1456
Poll Maker Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

CVE-2022-1170
Noo JobMonster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-79 1 PoC

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

CVE-2022-3140
LibreOffice Windows
N/A
UNKNOWN
EPSS
1.3%
2022 CWE-20 1 PoC

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.

CVE-2022-1685
Five Minute Webshop Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection

CVE-2022-0168
kernel Windows
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-476 1 PoC

A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.

CVE-2022-1218
Domain Replace Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-2118
404s Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-1089
Bulk Edit and Create User Profiles – WP Sheet Editor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed