7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4226
Simple Basic Contact Form Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3074
Slider Hero with Animation, Video Background Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

CVE-2022-3828
Video Thumbnails Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Thumbnails WordPress plugin through 2.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3426
Advanced WP Columns Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-46428
Software Genérico General
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

CVE-2022-39911
Samsung Pass General
4.8
MEDIUM
EPSS
0.1%
2022 CWE-703 1 PoC

Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.

CVE-2022-50906
e107 CMS Web
4.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads that can execute arbitrary scripts when viewed.

CVE-2022-42095
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
42.1%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVE-2022-3834
Google Forms Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-29418
Night Mode (WordPress plugin) Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].

CVE-2022-3833
Fancier Author Box by ThematoSoup Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-36137
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.

CVE-2022-3135
SEO Smart Links Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-23059
Shopizer Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.

CVE-2022-45223
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 2 PoCs

Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.

CVE-2022-41445
Software Genérico Web
4.8
MEDIUM
EPSS
1.6%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.

CVE-2022-40470
Software Genérico Web
4.8
MEDIUM
EPSS
3.6%
2022 2 PoCs

Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

CVE-2022-4981
DCMTK General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-476 2 PoCs

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit is now public and may be used. Upgrading to version 3.6.8 is sufficient to resolve this issue. The patch is identified as 957fb31e5. Upgrading the affected component is advised.

CVE-2022-3469
WP Attachments Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-4199
Link Library Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).