550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0437
karma-runner/karma Web ⚡ nuclei
5.4
MEDIUM
EPSS
24.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.

CVE-2022-36923
Software Genérico Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
32.5%
2022 0 PoCs

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

CVE-2022-27849
Simple Ajax Chat (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
11.3%
2022 CWE-200 0 PoCs

Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

CVE-2022-28666
Custom Product Tabs for WooCommerce (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
8.8%
2022 CWE-287 0 PoCs

Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.

CVE-2022-41697
Ghost Web ⚡ nuclei
5.3
MEDIUM
EPSS
18.6%
2022 CWE-204 1 PoC

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2022-24819
xwiki-platform General ⚡ nuclei
5.3
MEDIUM
EPSS
4.3%
2022 CWE-359 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

CVE-2022-1815
jgraph/drawio General ⚡ nuclei
5.3
MEDIUM
EPSS
24.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

CVE-2022-2462
Transposh WordPress Translation Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
5.5%
2022 CWE-200 1 PoC

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.

CVE-2022-33901
MultiSafepay plugin for WooCommerce (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
10.2%
2022 0 PoCs

Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

CVE-2022-40443
Software Genérico Web ⚡ nuclei
5.3
MEDIUM
EPSS
12.2%
2022 0 PoCs

An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.

CVE-2022-0776
hakimel/reveal.js Web ⚡ nuclei
5.3
MEDIUM
EPSS
20.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.

CVE-2022-45354
Download Monitor General ⚡ nuclei
5.3
MEDIUM
EPSS
87.6%
2022 CWE-200 2 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

CVE-2022-2461
Transposh WordPress Translation Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
16.9%
2022 CWE-862 2 PoCs

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.

CVE-2022-4057
Autoptimize Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
45.4%
2022 1 PoC

The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.

CVE-2022-31711
vRealize Log Insight (vRLI) General ⚡ nuclei
5.3
MEDIUM
EPSS
81.7%
2022 1 PoC

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.

CVE-2022-0870
gogs/gogs General ⚡ nuclei
5.0
MEDIUM
EPSS
9.1%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2022-42095
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
42.1%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVE-2022-42094
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
38.0%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

CVE-2022-4260
WP-Ban Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
1.0%
2022 1 PoC

The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).