5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-33691
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-367 1 PoC

A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.

CVE-2022-21385
Oracle Linux Database
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVE-2022-28783
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

CVE-2022-40912
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

CVE-2022-45729
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.

CVE-2022-4320
WordPress Events Calendar Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
15.4%
2022 1 PoC

The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).

CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-40712
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2022 1 PoC

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.

CVE-2022-0381
Embed Swagger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
4.4%
2022 CWE-79 0 PoCs

The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.

CVE-2022-4897
BackupBuddy Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.7%
2022 1 PoC

The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting

CVE-2022-3149
WP Custom Cursors Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

CVE-2022-3904
MonsterInsights Web Windows
6.1
MEDIUM
EPSS
41.3%
2022 2 PoCs

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVE-2022-21258
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle

CVE-2022-43369
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.

CVE-2022-4295
Show All Comments Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2022 1 PoC

The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2022-21458
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navigation Pages, Portal, Query). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can resul

CVE-2022-4552
FL3R FeelBox Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2022-45176
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.

CVE-2022-45144
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Algoo Tracim before 4.4.2 allows XSS via HTML file upload.

CVE-2022-4325
Post Status Notifier Lite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2022 1 PoC

The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.