7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4623
ND Shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-25018
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2022 2 PoCs

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

CVE-2022-33911
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.

CVE-2022-0320
Essential Addons for Elementor Web Windows
N/A
UNKNOWN
EPSS
4.5%
2022 CWE-22 2 PoCs

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

CVE-2022-30313
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected components are characterized as: Honeywell Experion TCP (51000/TCP), Safety Builder (51010/TCP). The potential impact is: Manipulate controller state, Manipulate controller configuration, Manipulate controller logic, Manipulate controller files, Manipulate IO. The Honeywell Experion PKS Distributed Control System (DCS) Safety

CVE-2022-0191
Ad Invalid Click Protector (AICP) Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

CVE-2022-1843
MailPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

CVE-2022-39800
SAP BusinessObjects Business Intelligence Platform (BI LaunchPad) General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-79 1 PoC

SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-23074
recipes Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.

CVE-2022-34962
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2022 2 PoCs

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.

CVE-2022-1395
Easy FAQ with Expanding Text Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-0591
FormCraft Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2022 CWE-918 1 PoC

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

CVE-2022-31650
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.

CVE-2022-0779
User Meta – User Profile Builder and User management plugin Web Windows
N/A
UNKNOWN
EPSS
13.7%
2022 CWE-22 1 PoC

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads

CVE-2022-1763
Static Page eXtended Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

CVE-2022-30422
Software Genérico General
N/A
UNKNOWN
EPSS
6.6%
2022 1 PoC

Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.

CVE-2022-40306
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) before 5.5.2 (July 2023) performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.

CVE-2022-26183
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

CVE-2022-41392
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings.

CVE-2022-24342
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.