13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1219
pimcore/pimcore Web Database
7.2
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

CVE-2022-38715
QUARTZ-GOLD Web
7.2
HIGH
EPSS
7.5%
2022 CWE-489 2 PoCs

A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-4680
Revive Old Posts Web Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-4358
WP RSS By Publishers Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-36279
QUARTZ-GOLD Web
7.2
HIGH
EPSS
8.9%
2022 CWE-120 2 PoCs

A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1429
pimcore/pimcore Web Database
7.2
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data

CVE-2022-42278
NVIDIA DGX servers Web
7.2
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-3490
Checkout Field Editor (Checkout Manager) for WooCommerce Web Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

CVE-2022-3335
Kadence WooCommerce Email Designer Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-3418
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
1.4%
2022 CWE-94 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files

CVE-2022-4373
Quote-O-Matic Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The Quote-O-Matic WordPress plugin through 1.0.5 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2022-3302
Spam protection, AntiSpam, FireWall by CleanTalk Web Networking Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin

CVE-2022-43229
Software Genérico Web Database
7.2
HIGH
EPSS
0.4%
2022 1 PoC

Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.

CVE-2022-3925
buddybadges Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-42279
NVIDIA DGX servers Web
7.2
HIGH
EPSS
0.6%
2022 CWE-78 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-21395
Communications Operations Monitor Web Database
7.2
HIGH
EPSS
1.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-39045
QUARTZ-GOLD Web
7.2
HIGH
EPSS
3.3%
2022 CWE-22 2 PoCs

A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-31109
laminas-diactoros Web
7.2
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a `Laminas\Diactoros\Uri` instance associated with the incoming server request modified to reflect values from `X-Forwarded-*` headers. Such changes can potentially lead to XSS attacks (if a fully-qualified URL is used in links) and/or URL poisoning. Since the `X-Forwarded-*` headers do hav

CVE-2022-42289
NVIDIA DGX servers Web
7.2
HIGH
EPSS
0.8%
2022 CWE-78 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-43279
Software Genérico Web Database
7.2
HIGH
EPSS
0.3%
2022 1 PoC

LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.