7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4306
Panda Pods Repeater Field Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.3%
2022 1 PoC

The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.

CVE-2022-42099
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.

CVE-2022-44380
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.

CVE-2022-46087
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.5%
2022 2 PoCs

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

CVE-2022-4459
WP Show Posts Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Show Posts WordPress plugin before 1.1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4473
Widget Shortcode Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4658
RSSImport Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4477
Smash Balloon Social Post Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-44284
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).

CVE-2022-4835
Social Sharing Toolkit Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21242
Primavera Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulne

CVE-2022-0589
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.

CVE-2022-41431
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.

CVE-2022-41446
Software Genérico Web
5.4
MEDIUM
EPSS
3.1%
2022 2 PoCs

An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify user data.

CVE-2022-4570
Top 10 Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Top 10 WordPress plugin before 3.2.3 does not validate and escape some of its Block attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-33927
Wyse Management Suite General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.

CVE-2022-21238
InRouter302 Web Networking
5.4
MEDIUM
EPSS
2.0%
2022 CWE-80 1 PoC

A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-3983
Checkout for PayPal Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-39420
Transportation Management Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Functional Security). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base S

CVE-2022-22331
SterlingPartner Engagement Manager General
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.