550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-3062
Simple File List Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
48.7%
2022 CWE-79 1 PoC

The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

CVE-2022-41473
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
19.0%
2022 0 PoCs

RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.

CVE-2022-28923
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
2.9%
2022 0 PoCs

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

CVE-2022-46934
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
12.9%
2022 0 PoCs

kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.

CVE-2022-4971
Social Sharing Plugin – Sassy Social Share Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 CWE-79 1 PoC

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2022-43014
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.

CVE-2022-40879
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.4%
2022 0 PoCs

kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'

CVE-2022-48012
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
4.6%
2022 0 PoCs

Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.

CVE-2022-3578
ProfileGrid – User Profiles, Memberships, Groups and Communities Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
6.4%
2022 CWE-79 1 PoC

The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-43017
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

CVE-2022-40359
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
9.2%
2022 1 PoC

Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.

CVE-2022-24682
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
88.0%
2022 0 PoCs

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CVE-2022-38467
CRM Perks Forms – WordPress Form Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
17.7%
2022 CWE-79 0 PoCs

Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

CVE-2022-43015
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

CVE-2022-43016
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.4%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

CVE-2022-42747
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-4321
PDF Generator for WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 1 PoC

The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin

CVE-2022-27926
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
94.1%
2022 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

CVE-2022-39195
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
10.0%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.

CVE-2022-3908
Plug your WooCommerce into the largest catalog of customized print products from Helloprint Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.9%
2022 1 PoC

The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting