7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1090
Good & Bad comments Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-0771
SiteSuperCharger Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

CVE-2022-39817
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.

CVE-2022-47532
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.

CVE-2022-2373
Simply Schedule Appointments – WordPress Booking Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2022 CWE-862 1 PoC

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

CVE-2022-2754
Ketchup Restaurant Reservations Web Database Windows
N/A
UNKNOWN
EPSS
4.4%
2022 CWE-89 1 PoC

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

CVE-2022-2146
Import CSV Files Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting

CVE-2022-0206
NewStatPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVE-2022-26252
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.6%
2022 1 PoC

aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).

CVE-2022-0769
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2022 CWE-89 1 PoC

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CVE-2022-31495
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.

CVE-2022-1320
Sliderby10Web Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-2655
Classified Listing Pro - Classified ads & Business Directory Plugin Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-37705
Software Genérico General
N/A
UNKNOWN
EPSS
4.8%
2022 1 PoC

A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),

CVE-2022-34305
Apache Tomcat Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.1%
2022 CWE-79 1 PoC

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

CVE-2022-0377
LearnPress Web Windows
N/A
UNKNOWN
EPSS
3.0%
2022 1 PoC

Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use this vulnerability in order to rename an arbitrary image file. By doing this, they could destroy the design o

CVE-2022-1294
IMDB Info Box Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-0252
GiveWP – Donation Plugin and Fundraising Platform Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2022-1594
HC Custom WP-Admin URL Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL

CVE-2022-26988
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.