3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0783
Multiple Shipping Address Woocommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.5%
2022 CWE-89 1 PoC

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

CVE-2022-38637
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

CVE-2022-0165
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2022 CWE-601 3 PoCs

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

CVE-2022-0149
WooCommerce – Store Exporter Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

CVE-2022-34046
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2022 2 PoCs

An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].

CVE-2022-25323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.7%
2022 0 PoCs

ZEROF Web Server 2.0 allows /admin.back XSS.

CVE-2022-0288
Ad Inserter – Ad Manager & AdSense Ads Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 CWE-79 1 PoC

The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-32025
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

CVE-2022-35413
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2022 2 PoCs

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

CVE-2022-1390
Admin Word Count Column Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2022 CWE-22 2 PoCs

The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique

CVE-2022-25485
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
37.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

CVE-2022-28290
WordPress Country Selector Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2022 CWE-79 1 PoC

Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request

CVE-2022-37153
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2022 1 PoC

An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.

CVE-2022-1946
Gallery – Image and Video Gallery with Thumbnails Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-79 1 PoC

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

CVE-2022-38812
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2022 1 PoC

AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.

CVE-2022-1595
HC Custom WP-Admin URL Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.0%
2022 CWE-200 1 PoC

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

CVE-2022-29349
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2022 0 PoCs

kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.

CVE-2022-37122
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.9%
2022 3 PoCs

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

CVE-2022-30073
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.6%
2022 0 PoCs

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.

CVE-2022-1756
Newsletter – Send awesome emails from WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2022 CWE-79 1 PoC

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.