5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4512
Better Font Awesome Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2022-46369
FTP server Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields.

CVE-2022-1420
vim/vim General
6.8
MEDIUM
EPSS
0.6%
2022 CWE-823 2 PoCs

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.

CVE-2022-0954
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
4.3%
2022 CWE-79 1 PoC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-30624
Chcnav - P5E GNSS General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.

CVE-2022-31898
Software Genérico General
6.8
MEDIUM
EPSS
22.4%
2022 2 PoCs

gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.

CVE-2022-2495
microweber/microweber Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2022-4764
Simple File Downloader Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4471
YARPP Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-28542
Galaxy Store General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.

CVE-2022-39051
OTRS General
6.8
MEDIUM
EPSS
0.5%
2022 CWE-913 1 PoC

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

CVE-2022-4682
Lightbox Gallery Web Windows
6.8
MEDIUM
EPSS
0.8%
2022 1 PoC

The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-0145
forkcms/forkcms Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.

CVE-2022-43096
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.

CVE-2022-38451
FreshTomato Web
6.8
MEDIUM
EPSS
4.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-4759
GigPress Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-36325
RUGGEDCOM RM1224 LTE(4G) EU Web
6.8
MEDIUM
EPSS
0.4%
2022 CWE-80 1 PoC

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

CVE-2022-0928
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
6.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-34674
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
6.8
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.