7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4242
WP Google Review Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3069
WordLift – AI powered SEO – Schema Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-22311
Security Verify Access General
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.

CVE-2022-4119
Image Optimizer, Resizer and CDN Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-30628
Supersmart.me – Walk Through Web
4.8
MEDIUM
EPSS
0.0%
2022 3 PoCs

It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX

CVE-2022-4196
Multi Step Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-21281
Primavera Portfolio Management Web Database
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vuln

CVE-2022-3906
Easy Form Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3237
WP Contact Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-45224
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.

CVE-2022-48615
AR6000 General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.

CVE-2022-2983
Salat Times Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-45221
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter.

CVE-2022-3609
GetYourGuide Ticketing Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-40846
Software Genérico Web Networking
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.

CVE-2022-3839
Analytics for WP Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-20967
Cisco Identity Services Engine Software Web Networking
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTM

CVE-2022-4010
Image Hover Effects Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3441
Rock Convert Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4200
Login with Cognito Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).