550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-35493
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 0 PoCs

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.

CVE-2022-1580
Site Offline Or Coming Soon Or Maintenance Mode Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.0%
2022 CWE-639 1 PoC

The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.

CVE-2022-0346
XML Sitemap Generator for Google Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2022 CWE-79 1 PoC

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

CVE-2022-25497
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

CVE-2022-38794
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2022 1 PoC

Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.

CVE-2022-34094
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php.

CVE-2022-1020
Product Table for WooCommerce (wooproducttable) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2022 CWE-862 1 PoC

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

CVE-2022-0899
Header Footer Code Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2022 CWE-79 1 PoC

The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-24181
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2022 2 PoCs

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVE-2022-31847
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
50.6%
2022 0 PoCs

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

CVE-2022-27043
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
25.5%
2022 0 PoCs

Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.

CVE-2022-31798
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.6%
2022 3 PoCs

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-34049
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
15.5%
2022 1 PoC

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

CVE-2022-29009
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 2 PoCs

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

CVE-2022-0656
Web To Print Shop : uDraw Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2022 CWE-552 1 PoC

The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

CVE-2022-29298
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 1 PoC

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

CVE-2022-1398
External Media without Import Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
40.5%
2022 CWE-918 1 PoC

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

CVE-2022-32444
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2022 0 PoCs

An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.

CVE-2022-22972
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 5 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-24264
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
23.7%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.