550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-32028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

CVE-2022-1170
Noo JobMonster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-79 1 PoC

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

CVE-2022-0412
TI WooCommerce Wishlist Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-89 2 PoCs

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

CVE-2022-0784
Title Experiments Free Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.9%
2022 CWE-89 1 PoC

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-27985
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-29004
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
39.7%
2022 1 PoC

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVE-2022-48165
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 0 PoCs

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2022-0949
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
62.5%
2022 CWE-89 1 PoC

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection

CVE-2022-0533
Ditty (formerly Ditty News Ticker) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2022 CWE-79 1 PoC

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-31854
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 3 PoCs

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

CVE-2022-0765
Loco Translate Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

CVE-2022-32195
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2022 0 PoCs

Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

CVE-2022-28032
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.7%
2022 0 PoCs

AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php

CVE-2022-34267
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.8%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.

CVE-2022-25489
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 0 PoCs

Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.

CVE-2022-32007
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.

CVE-2022-26271
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.7%
2022 0 PoCs

74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

CVE-2022-31299
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.0%
2022 1 PoC

Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.

CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-29005
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2022 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.