5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-33927
Wyse Management Suite General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.

CVE-2022-42710
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Nice (formerly Nortek) Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e devices are vulnerable to Stored Cross-Site Scripting (XSS).

CVE-2022-44951
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2022-1755
SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

CVE-2022-4765
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-0437
karma-runner/karma Web ⚡ nuclei
5.4
MEDIUM
EPSS
24.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.

CVE-2022-21477
Applications Framework Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthor

CVE-2022-43271
Software Genérico Web
5.4
MEDIUM
EPSS
1.1%
2022 1 PoC

Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component.

CVE-2022-42100
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.

CVE-2022-4675
Mongoose Page Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-22117
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.

CVE-2022-4831
Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4381
Popup Maker Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4667
RSS Aggregator by Feedzy Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21400
Communications Operations Monitor Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2022-35612
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field.

CVE-2022-43164
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.0%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVE-2022-44952
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".

CVE-2022-44957
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.