5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-48178
Software Genérico Web
5.4
MEDIUM
EPSS
1.9%
2022 1 PoC

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.

CVE-2022-4784
Hueman Addons Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4651
Justified Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-28286
Thunderbird General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVE-2022-4762
Materialis Companion Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Materialis Companion WordPress plugin before 1.3.40 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4832
Store Locator WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-41542
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

devhub 0.102.0 was discovered to contain a broken session control.

CVE-2022-4479
Table of Contents Plus Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-45217
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.

CVE-2022-41049
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
13.1%
2022 3 PoCs

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-21397
Communications Operations Monitor Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2022-4480
Click to Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-48085
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.

CVE-2022-4656
WP Visitor Statistics (Real Time Traffic) Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4747
Post Category Image With Grid and Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-44949
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.

CVE-2022-22463
Security Verify Access Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.

CVE-2022-45892
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.

CVE-2022-4789
WPZOOM Portfolio Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-25854
@yaireo/tagify Web
5.4
MEDIUM
EPSS
0.8%
2022 1 PoC

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.