5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38201
ArcGIS Quickcapture General
6.1
MEDIUM
EPSS
0.4%
2022 CWE-601 1 PoC

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVE-2022-37306
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2022 1 PoC

OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.

CVE-2022-36316
Firefox Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.

CVE-2022-2654
Classified Listing – Classified ads & Business Directory Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

CVE-2022-4307
پلاگین پرداخت دلخواه Web Windows
6.1
MEDIUM
EPSS
1.1%
2022 1 PoC

The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin.

CVE-2022-42066
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.

CVE-2022-46095
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via verification.php because the program does not verify the txtvaccinationID parameter.

CVE-2022-33929
Wyse Management Suite Web
6.1
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

CVE-2022-4398
radareorg/radare2 General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.

CVE-2022-44002
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the web application is vulnerable to cross-site scripting (XSS) at various locations.

CVE-2022-0645
posthog/posthog General
6.1
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.

CVE-2022-23520
rails-html-sanitizer Web
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags to allow both "select" and "style" elements. Code is only impacted if allowed tags are being overridden. This issue is patched in version 1.4.4. All users overriding the allowed tags to include both "select" and "st

CVE-2022-21419
Business Intelligence Enterprise Edition Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.5.0.0.0 and 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Success

CVE-2022-21261
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to

CVE-2022-1257
McAfee Agent Windows
6.1
MEDIUM
EPSS
0.2%
2022 CWE-922 2 PoCs

Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

CVE-2022-41441
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.7%
2022 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.

CVE-2022-41207
SAP Biller Direct General
6.1
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or modification of the victim's information.

CVE-2022-20659
Cisco Prime Infrastructure Web Networking
6.1
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code i

CVE-2022-46381
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
81.5%
2022 2 PoCs

Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.