550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0189
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2022 CWE-79 1 PoC

The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-38296
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
71.5%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

CVE-2022-23881
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2022 0 PoCs

ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

CVE-2022-1574
HTML2WP Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.9%
2022 1 PoC

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

CVE-2022-24681
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.4%
2022 1 PoC

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

CVE-2022-2552
Duplicator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2022 2 PoCs

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

CVE-2022-1692
CP Image Store with Slideshow Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 2 PoCs

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

CVE-2022-26159
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 2 PoCs

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

CVE-2022-0208
MapPress Maps for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 CWE-79 1 PoC

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

CVE-2022-32429
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 4 PoCs

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.