3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4446
tsolucio/corebos Web
9.8
CRITICAL
EPSS
0.7%
2022 CWE-98 1 PoC

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2022-3477
tagDiv Composer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.5%
2022 CWE-287 1 PoC

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

CVE-2022-25299
cesanta/mongoose Web
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

CVE-2022-24627
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
48.7%
2022 0 PoCs

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

CVE-2022-32224
https://github.com/rails/rails Web Database
9.8
CRITICAL
EPSS
1.9%
2022 CWE-502 1 PoC

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

CVE-2022-48079
Software Genérico Web
9.8
CRITICAL
EPSS
1.5%
2022 2 PoCs

Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

CVE-2022-40030
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.

CVE-2022-43138
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

CVE-2022-47877
Software Genérico Web
9.6
CRITICAL
EPSS
8.0%
2022 1 PoC

A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.

CVE-2022-32771
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
10.0%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.

CVE-2022-30690
AVideo Web
9.6
CRITICAL
EPSS
9.8%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-41924
tailscale Web Windows
9.6
CRITICAL
EPSS
53.6%
2022 CWE-346 3 PoCs

A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TCP socket, and communicated with the Windows client GUI in cleartext with no Host header verification. This allowed an attacker-controlled website visited by the node to rebind DNS to an attacker-controlled DNS server, and then make local API requests in the client, including changing the coordination server to an attacker-controlled coordinati

CVE-2022-0153
forkcms/forkcms Web Database
9.6
CRITICAL
EPSS
0.3%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

CVE-2022-41654
Ghost Web
9.6
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-26842
AVideo Web
9.6
CRITICAL
EPSS
9.5%
2022 CWE-79 1 PoC

A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-3152
phpfusion/phpfusion Web
9.6
CRITICAL
EPSS
0.3%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.

CVE-2022-22759
Firefox Web
9.6
CRITICAL
EPSS
0.3%
2022 2 PoCs

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-36180
Software Genérico Web
9.6
CRITICAL
EPSS
0.2%
2022 1 PoC

Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.

CVE-2022-1347
causefx/organizr Web
9.6
CRITICAL
EPSS
0.5%
2022 CWE-79 1 PoC

Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation

CVE-2022-32772
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
7.8%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "msg" parameter which is inserted into the document with insufficient sanitization.