3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-39986
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2022 7 PoCs

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.

CVE-2022-0879
Caldera Forms – More Than Contact Forms Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-0147
Cookie Information | Free GDPR Consent Solution Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2022 CWE-79 1 PoC

The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVE-2022-0814
Ubigeo de Perú para Woocommerce y WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
58.2%
2022 CWE-89 1 PoC

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

CVE-2022-32018
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

CVE-2022-25216
DVDFab 12 Player / PlayerFab Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.7%
2022 2 PoCs

An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.

CVE-2022-31373
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 0 PoCs

SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.

CVE-2022-1580
Site Offline Or Coming Soon Or Maintenance Mode Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.0%
2022 CWE-639 1 PoC

The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.

CVE-2022-24181
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2022 2 PoCs

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVE-2022-0656
Web To Print Shop : uDraw Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2022 CWE-552 1 PoC

The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

CVE-2022-24264
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
23.7%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

CVE-2022-0948
Order Listener for WooCommerce – Play Sounds Instantly on New Orders Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 1 PoC

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

CVE-2022-36642
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.7%
2022 2 PoCs

A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.

CVE-2022-2168
Download Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 CWE-79 1 PoC

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-25322
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2022 0 PoCs

ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

CVE-2022-30514
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 2 PoCs

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.

CVE-2022-0658
CommonsBooking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
47.3%
2022 CWE-89 1 PoC

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

CVE-2022-26263
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2022 0 PoCs

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

CVE-2022-0873
Gmedia Photo Gallery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-79 1 PoC

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

CVE-2022-25486
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.