7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4597
LifeStyle Web
3.5
LOW
EPSS
0.4%
2022 CWE-707 2 PoCs

A vulnerability, which was classified as problematic, was found in Shoplazza LifeStyle 1.1. Affected is an unknown function of the file /admin/api/admin/v2_products of the component Create Product Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216192.

CVE-2022-3949
Simple Cashiering System General
3.5
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability, which was classified as problematic, has been found in Sourcecodester Simple Cashiering System. This issue affects some unknown processing of the component User Account Handler. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-213455.

CVE-2022-3376
ikus060/rdiffweb General
3.5
LOW
EPSS
0.5%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

CVE-2022-4347
beetl-bbs General
3.5
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215107.

CVE-2022-2293
Simple Sales Management System Web
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manipulation of the argument customer_name with the input <script>alert("XSS")</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-2683
Simple Food Ordering System Web
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Food Ordering System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password with the input "><ScRiPt>alert(1)</sCrIpT> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205671.

CVE-2022-4350
MCMS Web
3.5
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215112.

CVE-2022-3493
Human Resource Management System General
3.5
LOW
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210773 was assigned to this vulnerability.

CVE-2022-4736
Venganzas del Pasado General
3.5
LOW
EPSS
0.4%
2022 CWE-79 1 PoC

A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument the_title leads to cross site scripting. The attack may be launched remotely. The name of the patch is 62339b2ec445692c710b804bdf07aef4bd247ff7. It is recommended to apply a patch to fix this issue. VDB-216770 is the identifier assigned to this vulnerability.

CVE-2022-2691
Wedding Hall Booking System General
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in SourceCodester Wedding Hall Booking System. Affected by this issue is some unknown functionality of the file /whbs/?page=manage_account of the component Profile Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205814 is the identifier assigned to this vulnerability.

CVE-2022-3288
GitLab DevOps
3.5
LOW
EPSS
0.1%
2022 1 PoC

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVE-2022-2843
Timetable and Event Schedule Web
3.5
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/admin-ajax.php of the component Quick Edit. The manipulation of the argument post_title with the input <img src=x onerror=alert`2`> leads to cross site scripting. The attack may be launched remotely. VDB-206486 is the identifier assigned to this vulnerability.

CVE-2022-1536
automad General
3.5
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

CVE-2022-1979
Product Show Room Site General
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulnerability affects p=contact. The manipulation of the Message textbox with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires authentication. Exploit details have been disclosed to the public.

CVE-2022-2396
Simple e-Learning System General
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>alert(document.cookie)</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-2087
Bank Management System Web
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Bank Management System 1.0. This affects the file /mnotice.php?id=2. The manipulation of the argument notice with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-4377
S-CMS Web
3.5
LOW
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215197 was assigned to this vulnerability.

CVE-2022-0697
archivy/archivy General
3.4
LOW
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.

CVE-2022-4067
librenms/librenms Web
3.4
LOW
EPSS
87.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-4069
librenms/librenms Web
3.4
LOW
EPSS
66.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.