3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4109
Wholesale Market for WooCommerce Web Windows
2.7
LOW
EPSS
0.3%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

CVE-2022-39409
Transportation Management Web Database
2.7
LOW
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVE-2022-46498
Software Genérico Web Database
2.7
LOW
EPSS
0.1%
2022 1 PoC

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

CVE-2022-3521
Kernel Web
2.6
LOW
EPSS
0.0%
2022 CWE-362 1 PoC

A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability.

CVE-2022-28681
PDF Reader Web
2.5
LOW
EPSS
0.7%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the deletePages method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16825.

CVE-2022-0986
hestiacp/hestiacp Web
2.4
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

CVE-2022-1840
Home Clean Services Management System Web
2.4
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but demands authentication. Exploit details have been disclosed to the public.

CVE-2022-4053
Student Attendance Management System Web
2.4
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.

CVE-2022-0430
httpie/httpie Web
2.4
LOW
EPSS
0.3%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.

CVE-2022-31628
PHP Web
2.3
LOW
EPSS
0.0%
2022 CWE-674 1 PoC

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVE-2022-4614
alagrede/znote-app Web
2.3
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11.

CVE-2022-29247
electron Web
2.2
LOW
EPSS
0.8%
2022 CWE-668 1 PoC

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with `nodeIntegrationInSubFrames` enabled which in turn allows effective access to `ipcRenderer`. The `nodeIntegrationInSubFrames` option does not implicitly grant Node.js access. Rather, it depends on the existing sandbox setting. If an application is sandboxed, then `nodeIntegrationInSubFrames` just gives access to the sandboxed

CVE-2022-29836
My Cloud Home Web Cloud
1.9
LOW
EPSS
0.2%
2022 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could also allow the attacker to initiate the installation of custom packages at these locations. This can only be exploited once the attacker has been authenticated to the device. This issue affects: Western Digital My Cloud Home and My Cloud Home Duo versions prior to 8.11.0-113 on Lin

CVE-2022-31373
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 0 PoCs

SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.

CVE-2022-3021
Slickr Flickr Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Slickr Flickr WordPress plugin through 2.8.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0205
YOP Poll Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

CVE-2022-1598
WPQA Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
31.6%
2022 2 PoCs

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

CVE-2022-0952
Sitemap by click5 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2022 2 PoCs

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

CVE-2022-26565
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.

CVE-2022-47502
Apache OpenOffice Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.