3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-24129
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
22.8%
2022 0 PoCs

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

CVE-2022-0150
WP Accessibility Helper (WAH) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

CVE-2022-25082
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2022 0 PoCs

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVE-2022-34045
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.3%
2022 0 PoCs

Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.

CVE-2022-2535
SearchWP Live Ajax Search Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
18.4%
2022 CWE-639 1 PoC

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

CVE-2022-24266
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
37.4%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

CVE-2022-27927
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2022 2 PoCs

A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.

CVE-2022-2379
Easy Student Results Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
36.5%
2022 CWE-862 1 PoC

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

CVE-2022-0786
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.2%
2022 CWE-89 1 PoC

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

CVE-2022-0591
FormCraft Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2022 CWE-918 1 PoC

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

CVE-2022-0769
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2022 CWE-89 1 PoC

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CVE-2022-34305
Apache Tomcat Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.1%
2022 CWE-79 1 PoC

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

CVE-2022-0148
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2022 CWE-79 1 PoC

The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

CVE-2022-36883
Jenkins Git Plugin DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
78.6%
2022 0 PoCs

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

CVE-2022-33119
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2022 0 PoCs

NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.

CVE-2022-23944
Apache ShenYu (incubating) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2022 CWE-862 0 PoCs

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

CVE-2022-23779
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2022 2 PoCs

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

CVE-2022-29299
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-1597
WPQA Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
23.5%
2022 CWE-79 2 PoCs

The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacks