5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28353
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2022 1 PoC

In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.

CVE-2022-42747
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-43016
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.4%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

CVE-2022-30519
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2022 2 PoCs

XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

CVE-2022-21468
Applications Framework Web Database
6.1
MEDIUM
EPSS
1.2%
2022 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popups). Supported versions that are affected are 12.2.4-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, inse

CVE-2022-36182
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2022 2 PoCs

Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.

CVE-2022-3440
Rock Convert Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting

CVE-2022-31889
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae.

CVE-2022-24227
Software Genérico Web
6.1
MEDIUM
EPSS
3.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.

CVE-2022-43015
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

CVE-2022-0198
stanfordnlp/corenlp General
6.1
MEDIUM
EPSS
0.2%
2022 CWE-611 1 PoC

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2022-4830
Paid Memberships Pro Web Windows
6.1
MEDIUM
EPSS
4.2%
2022 1 PoC

The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3362
ikus060/rdiffweb General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

CVE-2022-4310
Slimstat Analytics Web Windows
6.1
MEDIUM
EPSS
1.8%
2022 1 PoC

The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs

CVE-2022-0637
mozilla/pollbot General
6.1
MEDIUM
EPSS
0.2%
2022 2 PoCs

open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6

CVE-2022-34474
Firefox General
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.

CVE-2022-3578
ProfileGrid – User Profiles, Memberships, Groups and Communities Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
6.4%
2022 CWE-79 1 PoC

The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-21409
JD Edwards EnterpriseOne Tools Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update,

CVE-2022-48020
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.

CVE-2022-4374
Bg Bible References Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The Bg Bible References WordPress plugin through 3.8.14 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.