3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-24260
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2022 0 PoCs

A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

CVE-2022-31268
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2022 0 PoCs

A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).

CVE-2022-0422
White Label CMS Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

CVE-2022-28080
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
42.0%
2022 3 PoCs

Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.

CVE-2022-29007
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2022 2 PoCs

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

CVE-2022-0867
Pricing Table Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2022 CWE-89 1 PoC

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

CVE-2022-28079
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2022 2 PoCs

College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.

CVE-2022-35416
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2022 1 PoC

H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

CVE-2022-48197
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.7%
2022 2 PoCs

Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2022-0781
Nirweb support Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.9%
2022 CWE-89 1 PoC

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

CVE-2022-31846
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2022 0 PoCs

A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVE-2022-32026
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.

CVE-2022-1013
Personal Dictionary Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2022 CWE-89 1 PoC

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

CVE-2022-28117
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
67.1%
2022 4 PoCs

A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

CVE-2022-32015
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.

CVE-2022-1391
Cab fare calculator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.7%
2022 CWE-22 2 PoCs

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

CVE-2022-0169
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.2%
2022 CWE-89 2 PoCs

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVE-2022-1933
CDI – Collect and Deliver Interface for Woocommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.5%
2022 CWE-79 1 PoC

The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVE-2022-35151
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2022 0 PoCs

kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.

CVE-2022-0479
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.4%
2022 CWE-89 1 PoC

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link