3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-30776
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
45.5%
2022 2 PoCs

atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.

CVE-2022-26585
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 1 PoC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

CVE-2022-1950
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.7%
2022 CWE-89 1 PoC

The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

CVE-2022-28987
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.2%
2022 0 PoCs

Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.

CVE-2022-34048
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 0 PoCs

Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.

CVE-2022-27228
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2022 1 PoC

In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

CVE-2022-1904
Pricing Tables WordPress Plugin – Easy Pricing Tables Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 CWE-79 1 PoC

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

CVE-2022-2034
Sensei LMS Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
33.7%
2022 1 PoC

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

CVE-2022-1168
WP JobSearch Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2022 CWE-79 1 PoC

There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

CVE-2022-32409
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
66.5%
2022 1 PoC

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

CVE-2022-34576
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
37.8%
2022 0 PoCs

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

CVE-2022-32430
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.9%
2022 0 PoCs

An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

CVE-2022-41678
Apache ActiveMQ Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2022 CWE-287 2 PoCs

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequestHandler#executeRequest. Into deeper calling stacks, org.jolokia.handler.ExecHandler#doHandleRequest can be invoked through refection. This could lead to RCE through via various mbeans. One example is unrestricted deserialization in jdk.man

CVE-2022-2863
Migration, Backup, Staging – WPvivid Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2022 CWE-22 2 PoCs

The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack

CVE-2022-1916
Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2022 CWE-79 1 PoC

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting

CVE-2022-31977
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.1%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVE-2022-39960
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2022 0 PoCs

The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI.

CVE-2022-25487
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2022 1 PoC

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

CVE-2022-0140
Visual Form Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.2%
2022 1 PoC

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

CVE-2022-29013
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2022 2 PoCs

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.