5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0196
phoronix-test-suite/phoronix-test-suite Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-42954
Software Genérico Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Keyfactor EJBCA before 7.10.0 allows XSS.

CVE-2022-0842
McAfee ePolicy Orchestrator (ePO) Database
5.4
MEDIUM
EPSS
0.2%
2022 CWE-89 1 PoC

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges.

CVE-2022-4468
WP Recipe Maker Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-3096
WP Total Hacks Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

CVE-2022-25929
smoothie Web
5.4
MEDIUM
EPSS
0.5%
2022 3 PoCs

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

CVE-2022-4751
Word Balloon Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21376
Primavera Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and 20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as

CVE-2022-40044
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

CVE-2022-4714
WP Dark Mode Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-36923
Software Genérico Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
32.5%
2022 0 PoCs

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

CVE-2022-4487
Easy Accordion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4783
Youtube Channel Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-21481
PeopleSoft Enterprise FIN Cash Management Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Financial Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Cash Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can resul

CVE-2022-4114
Superio Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.

CVE-2022-3326
ikus060/rdiffweb General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.

CVE-2022-4670
PDF.js Viewer Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The PDF.js Viewer WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4763
Icon Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4649
WP Extended Search Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-35134
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.