7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45472
Software Genérico Web
5.4
MEDIUM
EPSS
1.1%
2022 1 PoC

CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

CVE-2022-43167
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
5.9%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVE-2022-2729
openemr/openemr Web
5.4
MEDIUM
EPSS
3.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-4792
News & Blog Designer Pack Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4653
Greenshift Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4667
RSS Aggregator by Feedzy Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3025
Bitcoin / Altcoin Faucet Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-4666
Markup (JSON-LD) structured in schema.org Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-48178
Software Genérico Web
5.4
MEDIUM
EPSS
1.9%
2022 1 PoC

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.

CVE-2022-4483
Insert Pages Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4507
Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4627
ShiftNav Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21400
Communications Operations Monitor Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2022-21411
Database - Enterprise Edition Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the RDBMS Gateway / Generic ODBC Connectivity component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise RDBMS Gateway / Generic ODBC Connectivity. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS Gateway / Generic ODBC Connectivity accessible data as well as unauthorized read access to a subset of RDBMS Gateway / Generic ODBC

CVE-2022-41358
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 5 PoCs

A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

CVE-2022-35612
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field.

CVE-2022-41208
SAP Financial Consolidation General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.

CVE-2022-23068
ToolJet General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-74 1 PoC

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

CVE-2022-43770
Pentaho Business Analytics Server Web
5.4
MEDIUM
EPSS
0.4%
2022 CWE-863 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   

CVE-2022-43996
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently accessed via web browser, these advisories are served and interpreted as HTML pages. Such uploaded advisories can contain JavaScript code that will execute within the browser context of users inspecting the advisory.