5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-50937
Ametys CMS Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in link text and descriptions to execute persistent attacks that compromise user sessions and manipulate application modules.

CVE-2022-50683
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute in users' browsers through unvalidated form configuration settings.

CVE-2022-50680
Xperience Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to execute malicious scripts that could compromise user browsers and steal sensitive information.

CVE-2022-29840
My Cloud OS 5 Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud OS 5 devices before 5.26.202.

CVE-2022-50801
JF511-TV Web Networking
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing attackers with authenticated access to inject malicious scripts that will be executed in other users' browsers when they view the affected content.

CVE-2022-3172
kube-apiserver Web
5.1
MEDIUM
EPSS
2.8%
2022 CWE-918 1 PoC

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

CVE-2022-50964
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50958
Jetpack Web Windows
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.

CVE-2022-50965
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50960
International Sms For Contact Form Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress International Sms For Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.

CVE-2022-50969
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50962
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50945
real-time web stats Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress 3dady real-time web stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed.

CVE-2022-50966
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50949
Videos sync PDF Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options panel to execute arbitrary JavaScript when administrators view or edit video settings.

CVE-2022-50943
Moodle LMS Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVE-2022-50963
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50959
Contact Form Builder Web Windows
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.

CVE-2022-50968
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CVE-2022-50967
uBidAuction Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 2 PoCs

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.