550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-42096
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
21.4%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

CVE-2022-0692
rudloff/alltube General ⚡ nuclei
4.7
MEDIUM
EPSS
20.8%
2022 CWE-601 1 PoC

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

CVE-2022-2546
All-in-One WP Migration Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
16.2%
2022 5 PoCs

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

CVE-2022-29548
Software Genérico Web ⚡ nuclei
4.6
MEDIUM
EPSS
76.4%
2022 3 PoCs

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.

CVE-2022-0869
nitely/spirit General ⚡ nuclei
4.3
MEDIUM
EPSS
7.4%
2022 CWE-601 1 PoC

Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.

CVE-2022-3242
microweber/microweber General ⚡ nuclei
4.3
MEDIUM
EPSS
19.8%
2022 CWE-94 1 PoC

Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-0597
microweber/microweber General ⚡ nuclei
4.3
MEDIUM
EPSS
1.0%
2022 CWE-601 1 PoC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-35507
Software Genérico Web ⚡ nuclei
4.3
MEDIUM
EPSS
14.3%
2022 1 PoC

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

CVE-2022-25481
Software Genérico Web ⚡ nuclei
4.0
MEDIUM
EPSS
9.5%
2022 0 PoCs

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

CVE-2022-23134
🔥 KEV Frontend Web ⚡ nuclei
3.7
LOW
EPSS
92.6%
2022 CWE-284 1 PoC

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVE-2022-34590
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.

CVE-2022-34048
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 0 PoCs

Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.

CVE-2022-0595
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVE-2022-0760
Simple Link Directory Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.3%
2022 CWE-89 1 PoC

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-27228
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2022 1 PoC

In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

CVE-2022-0679
Narnoo Distributor Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2022 CWE-22 1 PoC

The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.

CVE-2022-0424
Popup by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.0%
2022 CWE-306 1 PoC

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

CVE-2022-25568
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.3%
2022 1 PoC

MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

CVE-2022-1952
Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-434 1 PoC

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.