5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4771
Pentaho Business Analytics Server General
5.4
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables. 

CVE-2022-3983
Checkout for PayPal Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4473
Widget Shortcode Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4477
Smash Balloon Social Post Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4577
Easy Testimonials Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4760
OneClick Chat to Order Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-44875
Software Genérico Web Windows
5.4
MEDIUM
EPSS
1.7%
2022 2 PoCs

KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.

CVE-2022-21629
JD Edwards EnterpriseOne Tools Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.6.4 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized upda

CVE-2022-43097
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages.

CVE-2022-46889
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web script or HTML via the title parameter used in /subtitles.php.

CVE-2022-4626
PPWP Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4752
Opening Hours Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-45096
PowerScale OneFS General
5.4
MEDIUM
EPSS
0.7%
2022 CWE-355 1 PoC

Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information.

CVE-2022-4544
Social Media Share Buttons | MashShare Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4671
PixCodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-36432
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.

CVE-2022-4699
MediaElement.js Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high-privilege users such as admins.

CVE-2022-3774
Train Scheduler App General
5.4
MEDIUM
EPSS
0.5%
2022 CWE-99 2 PoCs

A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource identifiers. The attack may be launched remotely. The identifier of this vulnerability is VDB-212504.

CVE-2022-0575
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-4775
GeoDirectory Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.