7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3753
Evaluate Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-33727
Samsung Mobile Devices General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-1021 1 PoC

A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

CVE-2022-3392
WP Humans.txt Web Windows
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-32769
AVideo Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Playlists plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's playlists.

CVE-2022-40711
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users.

CVE-2022-3830
WP Page Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-42097
Software Genérico Web
4.8
MEDIUM
EPSS
0.6%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

CVE-2022-40435
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.

CVE-2022-3466
Red Hat OpenShift Container Platform 4.12 DevOps Web
4.8
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

CVE-2022-3831
reCAPTCHA Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4142
WordPress Filter Gallery Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.

CVE-2022-23060
Shopizer Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

CVE-2022-3610
Jeeng Push Notifications Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4299
Metricool Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Metricool WordPress plugin before 1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-23179
Contact Form & Lead Form Elementor Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3840
Login for Google Apps Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4442
Custom Post Types and Custom Fields creator Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-3350
Contact Bank – Contact Form Builder for WordPress Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0132
chocobozzz/peertube General
4.8
MEDIUM
EPSS
0.3%
2022 CWE-918 1 PoC

peertube is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2022-22125
halo Web
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.