3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-25237
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2022 1 PoC

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

CVE-2022-37061
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2022 4 PoCs

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct

CVE-2022-23849
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.

CVE-2022-28994
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.

CVE-2022-4265
Replyable Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dismiss_notice action and also lacks CSRF check in the related action. This could allow any authenticated users, such as subscriber to perform Object Injection attacks. The attack could also be done via a CSRF vector against any authenticated user

CVE-2022-26982
Software Genérico Web
N/A
UNKNOWN
EPSS
10.5%
2022 1 PoC

SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose any PHP code that they wish to have executed on the server.

CVE-2022-29347
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

CVE-2022-0429
WP Cerber Security, Anti-spam & Malware Scan Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

CVE-2022-23047
Exponent CMS Web
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

CVE-2022-39814
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

CVE-2022-29153
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.8%
2022 2 PoCs

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

CVE-2022-0441
MasterStudy LMS – WordPress LMS Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 CWE-269 5 PoCs

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

CVE-2022-0994
Hummingbird – Optimize Speed, Enable Cache, Minify CSS & Defer Critical JS Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1953
Product Configurator for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
3.9%
2022 CWE-22 1 PoC

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

CVE-2022-3125
Frontend File Manager Plugin Web Windows
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-434 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

CVE-2022-0142
Visual Form Builder Web Windows
N/A
UNKNOWN
EPSS
4.7%
2022 CWE-1236 1 PoC

The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVE-2022-28962
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.

CVE-2022-2423
DW Promobar Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-24288
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2022 CWE-78 0 PoCs

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

CVE-2022-0447
Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting