3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0439
Email Subscribers & Newsletters Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.2%
2022 2 PoCs

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

CVE-2022-0535
E2Pdf – Export To Pdf Tool for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 CWE-79 1 PoC

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-37299
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.1%
2022 0 PoCs

An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php

CVE-2022-22897
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2022 2 PoCs

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.

CVE-2022-34121
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

CVE-2022-2551
Duplicator – WordPress Migration Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.7%
2022 CWE-425 2 PoCs

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.

CVE-2022-30489
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
28.8%
2022 2 PoCs

WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.

CVE-2022-0189
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2022 CWE-79 1 PoC

The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-38296
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
71.5%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

CVE-2022-23881
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2022 0 PoCs

ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

CVE-2022-1574
HTML2WP Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.9%
2022 1 PoC

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

CVE-2022-24681
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.4%
2022 1 PoC

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

CVE-2022-2552
Duplicator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2022 2 PoCs

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

CVE-2022-1692
CP Image Store with Slideshow Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 2 PoCs

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

CVE-2022-26159
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 2 PoCs

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

CVE-2022-0208
MapPress Maps for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 CWE-79 1 PoC

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

CVE-2022-32429
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 4 PoCs

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.

CVE-2000-0114
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.5%
2000 4 PoCs

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.

CVE-2000-0760
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
30.4%
2000 0 PoCs

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

CVE-2006-3392
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
78.6%
2006 9 PoCs

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.