3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-38794
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2022 1 PoC

Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.

CVE-2022-0899
Header Footer Code Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2022 CWE-79 1 PoC

The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-31798
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.6%
2022 3 PoCs

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-29009
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 2 PoCs

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

CVE-2022-38817
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2022 0 PoCs

Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

CVE-2022-2414
Dogtag PKI Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2022 CWE-611 6 PoCs

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVE-2022-32022
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

CVE-2022-24223
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
27.5%
2022 1 PoC

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

CVE-2022-0846
SpeakOut! Email Petitions Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2022 CWE-89 1 PoC

The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-0747
Infographic Maker – iList Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.5%
2022 CWE-89 1 PoC

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-29153
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.8%
2022 2 PoCs

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

CVE-2022-0212
SpiderCalendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-79 1 PoC

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

CVE-2022-37191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.5%
2022 0 PoCs

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

CVE-2022-2376
Directorist – WordPress Business Directory Plugin with Classified Ads Listings Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.5%
2022 CWE-862 1 PoC

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

CVE-2022-0434
Page View Count Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2022 CWE-89 1 PoC

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

CVE-2022-32028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

CVE-2022-0784
Title Experiments Free Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.9%
2022 CWE-89 1 PoC

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-29004
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
39.7%
2022 1 PoC

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVE-2022-0765
Loco Translate Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

CVE-2022-34267
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.8%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.