3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-29005
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2022 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVE-2022-28365
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.2%
2022 2 PoCs

Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.

CVE-2022-0594
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
44.0%
2022 CWE-863 1 PoC

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

CVE-2022-1724
Simple Membership Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2022 CWE-79 1 PoC

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

CVE-2022-0206
NewStatPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVE-2022-28033
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
58.4%
2022 0 PoCs

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

CVE-2022-27984
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-0595
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVE-2022-1952
Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-434 1 PoC

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.

CVE-2022-1054
RSVP and Event Management Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.7%
2022 CWE-862 1 PoC

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events

CVE-2022-0864
UpdraftPlus WordPress Backup Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2022 CWE-79 2 PoCs

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-31269
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.0%
2022 4 PoCs

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

CVE-2022-1906
Copyright Proof Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting when a specific setting is enabled.

CVE-2022-28955
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2022 1 PoC

An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.

CVE-2022-0693
Master Elements Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2022 CWE-89 1 PoC

The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

CVE-2022-31260
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
24.8%
2022 0 PoCs

In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.

CVE-2022-38131
RStudio Connect General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2022 1 PoC

RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.

CVE-2022-22733
Apache ShardingSphere ElasticJob-UI Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.

CVE-2022-1910
Shortcodes and extra features for Phlox theme Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2022 CWE-79 1 PoC

The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting