7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-42118
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
13.2%
2022 1 PoC

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.

CVE-2022-25479
Software Genérico General
6.1
MEDIUM
EPSS
2.8%
2022 2 PoCs

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.

CVE-2022-4310
Slimstat Analytics Web Windows
6.1
MEDIUM
EPSS
1.8%
2022 1 PoC

The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs

CVE-2022-21386
WebLogic Server DevOps Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized updat

CVE-2022-1254
Secure Web Gateway Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy.

CVE-2022-2015
jgraph/drawio Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.

CVE-2022-0764
strapi/strapi Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-78 1 PoC

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

CVE-2022-21492
Business Intelligence Enterprise Edition Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks

CVE-2022-2404
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-41376
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.

CVE-2022-42071
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.

CVE-2022-39197
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
19.6%
2022 12 PoCs

An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).

CVE-2022-24682
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
88.0%
2022 0 PoCs

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CVE-2022-38201
ArcGIS Quickcapture General
6.1
MEDIUM
EPSS
0.4%
2022 CWE-601 1 PoC

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVE-2022-26531
USG/ZyWALL series firmware Networking Cloud
6.1
MEDIUM
EPSS
1.0%
2022 CWE-20 2 PoCs

Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D fir

CVE-2022-21269
Primavera Portfolio Management Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vuln

CVE-2022-21639
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
1.5%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search Integration). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in

CVE-2022-4374
Bg Bible References Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The Bg Bible References WordPress plugin through 3.8.14 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-3904
MonsterInsights Web Windows
6.1
MEDIUM
EPSS
41.3%
2022 2 PoCs

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVE-2022-3362
ikus060/rdiffweb General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.