550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-29775
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.9%
2022 0 PoCs

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

CVE-2022-0234
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2022 CWE-79 1 PoC

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-25487
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2022 1 PoC

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

CVE-2022-32018
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

CVE-2022-1392
Videos sync PDF Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2022 CWE-22 2 PoCs

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

CVE-2022-1386
Fusion Builder Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 CWE-918 9 PoCs

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVE-2022-0140
Visual Form Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.2%
2022 1 PoC

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

CVE-2022-32024
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

CVE-2022-38295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
43.0%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

CVE-2022-1598
WPQA Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
31.6%
2022 2 PoCs

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

CVE-2022-32094
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.8%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.

CVE-2022-0952
Sitemap by click5 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2022 2 PoCs

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

CVE-2022-2599
Anti-Malware Security and Brute-Force Firewall Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
30.9%
2022 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-25216
DVDFab 12 Player / PlayerFab Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.7%
2022 2 PoCs

An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.

CVE-2022-29301
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-31373
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 0 PoCs

SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.

CVE-2022-34328
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.0%
2022 0 PoCs

PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

CVE-2022-29013
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2022 2 PoCs

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2022-29272
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2022 0 PoCs

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

CVE-2022-35653
Moodle Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.6%
2022 CWE-79 0 PoCs

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.