550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-40734
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2022 0 PoCs

UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.

CVE-2022-0827
Bestbooks Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.0%
2022 CWE-89 1 PoC

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-2187
Contact Form 7 Captcha Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2022 CWE-79 1 PoC

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2022-0594
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
44.0%
2022 CWE-863 1 PoC

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

CVE-2022-34093
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.5%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.

CVE-2022-31845
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
53.1%
2022 0 PoCs

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVE-2022-36883
Jenkins Git Plugin DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
78.6%
2022 0 PoCs

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

CVE-2022-34590
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.

CVE-2022-23944
Apache ShenYu (incubating) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2022 CWE-862 0 PoCs

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

CVE-2022-34048
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 0 PoCs

Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.

CVE-2022-31978
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.

CVE-2022-24129
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
22.8%
2022 0 PoCs

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

CVE-2022-28363
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2022 2 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

CVE-2022-0150
WP Accessibility Helper (WAH) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

CVE-2022-1724
Simple Membership Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2022 CWE-79 1 PoC

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

CVE-2022-0188
CMP Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 1 PoC

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

CVE-2022-25082
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2022 0 PoCs

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVE-2022-34045
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.3%
2022 0 PoCs

Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.

CVE-2022-2535
SearchWP Live Ajax Search Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
18.4%
2022 CWE-639 1 PoC

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

CVE-2022-0206
NewStatPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues