3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-42748
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-38553
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
30.7%
2022 2 PoCs

Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

CVE-2022-3908
Plug your WooCommerce into the largest catalog of customized print products from Helloprint Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.9%
2022 1 PoC

The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-42747
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-43016
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.4%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

CVE-2022-43015
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

CVE-2022-3578
ProfileGrid – User Profiles, Memberships, Groups and Communities Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
6.4%
2022 CWE-79 1 PoC

The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-43014
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.

CVE-2022-28923
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
2.9%
2022 0 PoCs

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

CVE-2022-22242
Junos OS Web Networking ⚡ nuclei
6.1
MEDIUM
EPSS
62.1%
2022 CWE-79 0 PoCs

A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21

CVE-2022-23397
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2022 0 PoCs

The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."

CVE-2022-48012
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
4.6%
2022 0 PoCs

Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.

CVE-2022-27926
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
94.1%
2022 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

CVE-2022-3484
wpb-show-core Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.5%
2022 CWE-79 1 PoC

The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-42746
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
3.0%
2022 0 PoCs

CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-42118
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
13.2%
2022 1 PoC

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.

CVE-2022-46073
Software Genérico DevOps Web ⚡ nuclei
6.1
MEDIUM
EPSS
29.5%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-40359
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
9.2%
2022 1 PoC

Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.

CVE-2022-4321
PDF Generator for WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 1 PoC

The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin