5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37462
Software Genérico Web Networking
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability in the Chat gadget in Upstream Works Agent Desktop for Cisco Finesse through 4.2.12 and 5.0 allows remote attackers to inject arbitrary web script or HTML via AttachmentId in the file-upload details.

CVE-2022-0727
chocobozzz/peertube General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

CVE-2022-4837
CPO Companion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3338
Trellix ePolicy Orchestrator (ePO) Web
5.4
MEDIUM
EPSS
0.4%
2022 CWE-611 1 PoC

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.

CVE-2022-4624
GS Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4652
Video Background Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-25847
serve-lite Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.

CVE-2022-4750
WP Responsive Testimonials Slider And Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4838
Clean Login Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4790
WP Google My Business Auto Publish Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44012
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferantenmanager before 5.6. An attacker can execute JavaScript code in the browser of the victim if a site is loaded. The victim's encrypted password can be stolen and most likely be decrypted.

CVE-2022-1753
WoWonder Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-284 3 PoCs

A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.

CVE-2022-21591
Transportation Management Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Ba

CVE-2022-30768
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

CVE-2022-43342
Software Genérico Web
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the KPI Title text field.

CVE-2022-4576
Easy Bootstrap Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-42119
Software Genérico Web
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.

CVE-2022-3025
Bitcoin / Altcoin Faucet Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-43166
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
4.5%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".

CVE-2022-4648
Real Testimonials Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.