5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4242
WP Google Review Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3408
WP Word Count Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-46430
Software Genérico General
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

CVE-2022-21281
Primavera Portfolio Management Web Database
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vuln

CVE-2022-22345
QRadar SIEM Web
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.

CVE-2022-3828
Video Thumbnails Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Thumbnails WordPress plugin through 2.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4010
Image Hover Effects Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4119
Image Optimizer, Resizer and CDN Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3829
Font Awesome 4 Menus Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-40029
Software Genérico Web
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.

CVE-2022-23060
Shopizer Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

CVE-2022-4042
Paytium: Mollie payment forms & donations Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-40490
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

CVE-2022-2563
Tutor LMS – eLearning and online course solution Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3823
Beautiful Cookie Consent Banner Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 2 PoCs

The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3892
WP OAuth Server (OAuth Authentication) Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3601
Image Hover Effects Css3 Web Cloud Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-50942
Incinga Web Web
4.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through the icinga.min.js file. Attackers can exploit the EventListener.handleEvent method to execute arbitrary scripts, potentially leading to session hijacking and non-persistent phishing attacks.

CVE-2022-33723
Samsung Mobile Devices General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-1021 1 PoC

A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

CVE-2022-0912
microweber/microweber General
4.8
MEDIUM
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.