1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-1532
Themify – WooCommerce Product Filter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-1889
Newsletter – Send awesome emails from WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

CVE-2022-3137
Taskbuilder – WordPress Project & Task Management plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file

CVE-2022-2543
Visual Portfolio, Photo Gallery & Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-862 1 PoC

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

CVE-2022-2638
Export All URLs Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-73 1 PoC

The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server

CVE-2022-0188
CMP Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 1 PoC

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

CVE-2022-4953
Elementor Website Builder Web Windows
N/A
UNKNOWN
EPSS
11.5%
2022 2 PoCs

The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.

CVE-2022-1562
Enable SVG Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVE-2022-23714
Endpoint Security Windows
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-264 1 PoC

A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

CVE-2022-0176
PowerPack Lite for Beaver Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0493
String locator Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-22 1 PoC

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

CVE-2022-1202
WP-CRM – Customer Relations Management for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-1236 1 PoC

The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.

CVE-2022-0594
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
44.0%
2022 CWE-863 1 PoC

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

CVE-2022-47631
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write access for the SYSTEM user. Although the service will not start if it detects malicious DLLs in this directory, attackers can exploit a race condition and replace a valid DLL (i.e., a copy of a legitimate Razer DLL) with a malicious DLL after the service has already checked the file. As a result, local Windows users can ab

CVE-2022-0720
Amelia – Events & Appointments Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-863 1 PoC

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

CVE-2022-1843
MailPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

CVE-2022-2873
Kernel Windows
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-131 1 PoC

An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.

CVE-2022-1977
Import Export All WordPress Images, Users & Post Types Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-918 1 PoC

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

CVE-2022-0186
Image Photo Gallery Final Tiles Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

CVE-2022-0199
Coming soon and Maintenance mode Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack