3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-34049
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
15.5%
2022 1 PoC

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

CVE-2022-29298
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 1 PoC

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

CVE-2022-1398
External Media without Import Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
40.5%
2022 CWE-918 1 PoC

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

CVE-2022-32444
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2022 0 PoCs

An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.

CVE-2022-22972
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 5 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-0349
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.5%
2022 CWE-89 1 PoC

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

CVE-2022-26564
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2022 0 PoCs

HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.

CVE-2022-1029
Limit Login Attempts Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

CVE-2022-0788
WP Fundraising Donation and Crowdfunding Platform Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.1%
2022 CWE-89 1 PoC

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users

CVE-2022-26960
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.2%
2022 0 PoCs

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

CVE-2022-3124
Frontend File Manager Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2022 CWE-862 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

CVE-2022-1937
Awin Data Feed Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2022 CWE-79 1 PoC

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVE-2022-2544
Ninja Job Board – Ultimate WordPress Job Board Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.5%
2022 CWE-425 2 PoCs

The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

CVE-2022-26148
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 0 PoCs

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVE-2022-1057
Pricing Deals for WooCommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.7%
2022 CWE-89 1 PoC

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

CVE-2022-31976
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.6%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.

CVE-2022-0599
Mapping multiple URLs redirect same page Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2022 CWE-79 1 PoC

The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-31470
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.0%
2022 1 PoC

An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.

CVE-2022-0201
Permalink Manager Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.9%
2022 CWE-79 1 PoC

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue

CVE-2022-29081
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2022 1 PoC

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.