7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0439
Email Subscribers & Newsletters Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.2%
2022 2 PoCs

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

CVE-2022-28862
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. This is fixed in all recent versions, such as version 26.2.

CVE-2022-0884
Profile Builder – User Profile & User Registration Forms Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-39015
SAP BusinessObjects Business Intelligence Platform (AdminTools/Query Builder) General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-668 1 PoC

Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.

CVE-2022-31478
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.

CVE-2022-24340
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

CVE-2022-2628
DSGVO All in one for WP Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1773
WP Athletics Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-2709
Float to Top Button Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-2374
Simply Schedule Appointments – WordPress Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-2357
WSM Downloader Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-552 1 PoC

The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.

CVE-2022-0657
5 Stars Rating Funnel WordPress Plugin | RRatingg Web Database Windows
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-89 1 PoC

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

CVE-2022-0535
E2Pdf – Export To Pdf Tool for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 CWE-79 1 PoC

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-40494
Software Genérico General
N/A
UNKNOWN
EPSS
8.2%
2022 1 PoC

NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.

CVE-2022-28533
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.

CVE-2022-0503
WordPress Multisite Content Copier/Updater Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in the network dashboard

CVE-2022-41522
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

CVE-2022-31213
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file.

CVE-2022-1921
GStreamer General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-190 1 PoC

Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.

CVE-2022-37063
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.