5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45613
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the publisher parameter.

CVE-2022-4476
Download Manager Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4481
Mesmerize Companion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4469
Simple Membership Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-40687
Creative Mail (WordPress plugin) Web Windows
5.4
MEDIUM
EPSS
1.4%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

CVE-2022-34021
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields.

CVE-2022-44380
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.

CVE-2022-26088
Software Genérico General
5.4
MEDIUM
EPSS
0.4%
2022 3 PoCs

An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated."

CVE-2022-0576
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.

CVE-2022-4475
Collapse-O-Matic Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-22116
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL.

CVE-2022-25782
GateManager General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-274 1 PoC

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-41358
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 5 PoCs

A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

CVE-2022-23068
ToolJet General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-74 1 PoC

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

CVE-2022-42141
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

CVE-2022-4451
Social Sharing Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4625
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-0822
orchardcms/orchardcore Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVE-2022-4551
Rich Table of Contents Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-44284
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).