550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0441
MasterStudy LMS – WordPress LMS Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 CWE-269 5 PoCs

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

CVE-2022-1595
HC Custom WP-Admin URL Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.0%
2022 CWE-200 1 PoC

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

CVE-2022-2376
Directorist – WordPress Business Directory Plugin with Classified Ads Listings Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.5%
2022 CWE-862 1 PoC

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

CVE-2022-24288
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2022 CWE-78 0 PoCs

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

CVE-2022-29349
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2022 0 PoCs

kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.

CVE-2022-0826
WP Video Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2022 CWE-89 1 PoC

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-31499
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2022 3 PoCs

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

CVE-2022-1221
Gwyn's Imagemap Selector Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-79 1 PoC

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

CVE-2022-37122
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.9%
2022 3 PoCs

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

CVE-2022-0434
Page View Count Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2022 CWE-89 1 PoC

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

CVE-2022-36553
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 1 PoC

Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

CVE-2022-30073
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.6%
2022 0 PoCs

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.

CVE-2022-1756
Newsletter – Send awesome emails from WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2022 CWE-79 1 PoC

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

CVE-2022-2314
VR Calendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2022 CWE-78 1 PoC

The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-0592
MapSVG Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 1 PoC

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVE-2022-38463
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
48.1%
2022 0 PoCs

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVE-2022-25226
ThinVNC Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2022 3 PoCs

ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.

CVE-2022-29014
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2022 2 PoCs

A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

CVE-2022-26233
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.0%
2022 2 PoCs

Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.