7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24728
ckeditor4 Web
5.4
MEDIUM
EPSS
1.0%
2022 CWE-79 2 PoCs

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVE-2022-25929
smoothie Web
5.4
MEDIUM
EPSS
0.5%
2022 3 PoCs

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

CVE-2022-4486
Meteor Slides Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4751
Word Balloon Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4485
Page-list Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4672
WordPress Simple Shopping Cart Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3937
Easy Video Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-4834
CPT Bootstrap Carousel Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-1755
SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

CVE-2022-44875
Software Genérico Web Windows
5.4
MEDIUM
EPSS
1.7%
2022 2 PoCs

KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.

CVE-2022-21376
Primavera Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and 20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as

CVE-2022-21572
Communications Billing and Revenue Management Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (sco

CVE-2022-3933
Essential Real Estate Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
5.5%
2022 1 PoC

The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.

CVE-2022-4391
Vision Interactive For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-40044
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

CVE-2022-43144
Software Genérico Web
5.4
MEDIUM
EPSS
2.0%
2022 3 PoCs

A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-4765
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4482
Carousel, Slider, Gallery by WP Carousel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-41206
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.

CVE-2022-42119
Software Genérico Web
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.