5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45223
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.

CVE-2022-40470
Software Genérico Web
4.8
MEDIUM
EPSS
3.6%
2022 2 PoCs

Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

CVE-2022-3469
WP Attachments Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-3069
WordLift – AI powered SEO – Schema Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3237
WP Contact Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-45224
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.

CVE-2022-48615
AR6000 General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.

CVE-2022-45221
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter.

CVE-2022-40846
Software Genérico Web Networking
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.

CVE-2022-3839
Analytics for WP Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-21263
Solaris Operating System Database
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fault Management Architecture). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data as well as unauthorized read access to a subset of Oracle Solaris

CVE-2022-3838
WPUpper Share Buttons Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3811
EU Cookie Law for GDPR/CCPA Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-46422
Software Genérico General
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

CVE-2022-32768
AVideo Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's streams.

CVE-2022-0209
Mitsol Social Post Feed Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-41445
Software Genérico Web
4.8
MEDIUM
EPSS
1.6%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.

CVE-2022-3135
SEO Smart Links Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-29418
Night Mode (WordPress plugin) Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].

CVE-2022-50906
e107 CMS Web
4.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads that can execute arbitrary scripts when viewed.