3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-34972
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.

CVE-2022-31455
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

* A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a user chat box.

CVE-2022-31415
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.

CVE-2022-27435
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

CVE-2022-31300
Software Genérico Web
N/A
UNKNOWN
EPSS
7.5%
2022 1 PoC

A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

CVE-2022-32013
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.

CVE-2022-37889
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; Web
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.

CVE-2022-1455
Call Now Button Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled

CVE-2022-25228
CandidATS Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=joborders&a=show' via the 'jobOrderID' and '/index.php?m=companies&a=show' via the 'companyID' parameter

CVE-2022-2378
Easy Student Results Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-27349
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2022 2 PoCs

Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-0442
UsersWP – User Registration & User Profile Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

CVE-2022-0590
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-36534
Software Genérico Web
N/A
UNKNOWN
EPSS
74.9%
2022 1 PoC

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.

CVE-2022-32244
SAP BusinessObjects Business Intelligence Platform (Commentary DB) Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-200 1 PoC

Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.

CVE-2022-37700
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2022 2 PoCs

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.

CVE-2022-29013
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2022 2 PoCs

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2022-29659
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 3 PoCs

Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

CVE-2022-0193
Complianz – GDPR/CCPA Cookie Consent Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 2 PoCs

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-35191
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.