7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4018
ikus060/rdiffweb General
6.1
MEDIUM
EPSS
0.4%
2022 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

CVE-2022-3908
Plug your WooCommerce into the largest catalog of customized print products from Helloprint Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.9%
2022 1 PoC

The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-3149
WP Custom Cursors Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

CVE-2022-27926
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
94.1%
2022 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

CVE-2022-21373
Partner Management Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Reseller Locator). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete acce

CVE-2022-43018
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.

CVE-2022-38553
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
30.7%
2022 2 PoCs

Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

CVE-2022-1618
Coru LFMember Web Windows
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads

CVE-2022-28354
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.

CVE-2022-21456
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navigation Pages, Portal, Query). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can resul

CVE-2022-50905
e107 CMS Web
6.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. An attacker can inject malicious JavaScript code through the URL parameter that gets executed when users click outside the comment field after typing content. The second vulnerability involves an upload restriction bypass for authenticated administrators, allowing them to upload SVG files containing malicious code through the media manager's remote

CVE-2022-43332
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

CVE-2022-45729
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.

CVE-2022-45176
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.

CVE-2022-23808
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
52.0%
2022 3 PoCs

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVE-2022-42748
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-25276
Core Web
6.1
MEDIUM
EPSS
2.3%
2022 1 PoC

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.

CVE-2022-4214
Chained Quiz Web Windows
6.1
MEDIUM
EPSS
1.8%
2022 CWE-79 1 PoC

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2022-21259
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to

CVE-2022-2404
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting