5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46428
Software Genérico General
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

CVE-2022-3833
Fancier Author Box by ThematoSoup Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-42974
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) attack on /file.bootloader.upload.html. The application fails to sanitize the parameter filename, in a POST request to /file.bootloader.upload.html for a system update, thus allowing one to inject HTML and/or JavaScript on the page that will then be processed and stored by the application. Any subsequent requests to pages that retrieve the malicious content will automatically exploit the vulnerability on the victim's browser. This also happens because the t

CVE-2022-3832
External Media Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-0132
chocobozzz/peertube General
4.8
MEDIUM
EPSS
0.3%
2022 CWE-918 1 PoC

peertube is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2022-3350
Contact Bank – Contact Form Builder for WordPress Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-23179
Contact Form & Lead Form Elementor Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3610
Jeeng Push Notifications Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3466
Red Hat OpenShift Container Platform 4.12 DevOps Web
4.8
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

CVE-2022-40711
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users.

CVE-2022-32769
AVideo Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Playlists plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's playlists.

CVE-2022-2251
GitLab Runner DevOps
4.8
MEDIUM
EPSS
2.2%
2022 1 PoC

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

CVE-2022-34451
PowerPath Management Appliance Web
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server.

CVE-2022-2574
Meks Easy Social Share Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3936
Team Members Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

CVE-2022-3824
WP Admin UI Customize Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3139
We’re Open! Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4200
Login with Cognito Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3609
GetYourGuide Ticketing Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-22311
Security Verify Access General
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.