3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-35493
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 0 PoCs

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.

CVE-2022-30513
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 2 PoCs

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

CVE-2022-37061
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2022 4 PoCs

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct

CVE-2022-34534
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
28.9%
2022 0 PoCs

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

CVE-2022-38295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
43.0%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

CVE-2022-1007
Advanced Booking Calendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.7%
2022 CWE-79 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2022-0533
Ditty (formerly Ditty News Ticker) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2022 CWE-79 1 PoC

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-28363
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2022 2 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

CVE-2022-0228
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 CWE-89 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

CVE-2022-23347
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

CVE-2022-0234
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2022 CWE-79 1 PoC

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-1598
WPQA Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
31.6%
2022 2 PoCs

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

CVE-2022-25497
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

CVE-2022-27043
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
25.5%
2022 0 PoCs

Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.

CVE-2022-0785
Daily Prayer Time Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.3%
2022 CWE-89 1 PoC

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-23348
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

CVE-2022-0826
WP Video Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2022 CWE-89 1 PoC

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-0592
MapSVG Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 1 PoC

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVE-2022-0412
TI WooCommerce Wishlist Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-89 2 PoCs

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

CVE-2022-25489
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 0 PoCs

Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.