7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4235
RushBet General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.

CVE-2022-4477
Smash Balloon Social Post Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-22117
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.

CVE-2022-4628
Easy PayPal Buy Now Button Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4666
Markup (JSON-LD) structured in schema.org Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4431
WOOCS Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3853
Supra CSV Web
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by including malicious code in a legitimate web page or web application.

CVE-2022-47102
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2022-39834
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2022 1 PoC

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.

CVE-2022-21377
Primavera Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web API). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and 20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as we

CVE-2022-25349
materialize-css Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

CVE-2022-4833
YourChannel: Everything you want in a YouTube plugin. Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-25978
github.com/usememos/memos/server Web
5.4
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.

CVE-2022-30003
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.

CVE-2022-3985
Videojs HTML5 Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4571
Seriously Simple Podcasting Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-44726
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.

CVE-2022-0756
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

CVE-2022-21398
Communications Operations Monitor Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2022-4474
Easy Social Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.