7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4658
RSSImport Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44284
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).

CVE-2022-4668
Easy Appointments Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4835
Social Sharing Toolkit Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21242
Primavera Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulne

CVE-2022-4458
amr shortcode any widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4570
Top 10 Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Top 10 WordPress plugin before 3.2.3 does not validate and escape some of its Block attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-33927
Wyse Management Suite General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.

CVE-2022-46087
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.5%
2022 2 PoCs

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

CVE-2022-21238
InRouter302 Web Networking
5.4
MEDIUM
EPSS
2.0%
2022 CWE-80 1 PoC

A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-39420
Transportation Management Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Functional Security). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base S

CVE-2022-22331
SterlingPartner Engagement Manager General
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.

CVE-2022-0196
phoronix-test-suite/phoronix-test-suite Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-0589
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.

CVE-2022-26088
Software Genérico General
5.4
MEDIUM
EPSS
0.4%
2022 3 PoCs

An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated."

CVE-2022-42954
Software Genérico Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Keyfactor EJBCA before 7.10.0 allows XSS.

CVE-2022-3935
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks

CVE-2022-21149
s-cart/s-cart Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

CVE-2022-4826
Simple Tooltips Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4578
Video Conferencing with Zoom Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.