1708 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3574
WPForms Pro Web Windows
9.8
CRITICAL
EPSS
1.3%
2022 CWE-1236 1 PoC

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

CVE-2022-46640
Software Genérico Web
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

CVE-2022-3634
Contact Form 7 Database Addon Web Windows
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

CVE-2022-40797
Software Genérico Web
9.8
CRITICAL
EPSS
12.6%
2022 1 PoC

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

CVE-2022-4047
Return Refund and Exchange For WooCommerce Web Windows
9.8
CRITICAL
EPSS
73.3%
2022 2 PoCs

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVE-2022-44003
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

CVE-2022-3915
Dokan Web Database Windows
9.8
CRITICAL
EPSS
3.2%
2022 1 PoC

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-4298
Wholesale Market Web Windows
9.8
CRITICAL
EPSS
55.7%
2022 1 PoC

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVE-2022-40471
Software Genérico Web
9.8
CRITICAL
EPSS
90.3%
2022 3 PoCs

Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

CVE-2022-3900
Cooked Pro Web Windows
9.8
CRITICAL
EPSS
4.3%
2022 1 PoC

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

CVE-2022-31692
Spring by VMware Web
9.8
CRITICAL
EPSS
7.4%
2022 3 PoCs

Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error

CVE-2022-4446
tsolucio/corebos Web
9.8
CRITICAL
EPSS
0.7%
2022 CWE-98 1 PoC

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2022-2932
bustle/mobiledoc-kit Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.

CVE-2022-33198
Accordions (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
31.2%
2022 CWE-264 0 PoCs

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

CVE-2022-40087
Software Genérico Web
9.8
CRITICAL
EPSS
1.0%
2022 3 PoCs

Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-25299
cesanta/mongoose Web
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

CVE-2022-24437
git-pull-or-clone Web
9.8
CRITICAL
EPSS
10.4%
2022 1 PoC

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

CVE-2022-39180
College Management System v1.0 Web Database
9.8
CRITICAL
EPSS
0.2%
2022 CWE-89 1 PoC

College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

CVE-2022-31691
Spring by VMware Web Cloud
9.8
CRITICAL
EPSS
10.9%
2022 2 PoCs

Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker.

CVE-2022-1609
school-management-pro Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2022 10 PoCs

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.