3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3766
thorsten/phpmyfaq Web ⚡ nuclei
7.3
HIGH
EPSS
18.6%
2022 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE-2022-2298
Clinics Patient Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument user_name with the input admin' or '1'='1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-2467
Garage Management System Web Database ⚡ nuclei
7.3
HIGH
EPSS
71.9%
2022 CWE-89 0 PoCs

A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-3118
ERP System Project Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some unknown processing of the file /pages/processlogin.php. The manipulation of the argument user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207845 was assigned to this vulnerability.

CVE-2022-0526
chatwoot/chatwoot Web
7.3
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

CVE-2022-3495
Simple Online Public Access Catalog Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210784.

CVE-2022-3878
ERP Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213039.

CVE-2022-1248
SAP Information System Web
7.3
HIGH
EPSS
0.6%
2022 CWE-287 2 PoCs

A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web application with a simple POST request. Exploit details were disclosed.

CVE-2022-28762
Zoom Client for Meetings for MacOS Web
7.3
HIGH
EPSS
0.2%
2022 CWE-16 1 PoC

Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.

CVE-2022-23000
My Cloud Web Networking Cloud
7.3
HIGH
EPSS
0.1%
2022 CWE-757 2 PoCs

The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was enabled to maintain compatibility with old or outdated home routers. By using an "SSL" context instead of "TLS" or specifying stronger validation, deprecated or insecure protocols are permitted. As a result, a local user with no privileges can exploit this vulnerability and jeopardize the integrity, confidentiality and authenticity of information transmitted. The scope of impact cannot extend to other components and no user input is required to exp

CVE-2022-21516
Enterprise Manager Base Platform Web Database
7.3
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data an

CVE-2022-3120
Clinics Patient Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System. Affected by this vulnerability is an unknown functionality of the file index.php of the component Login. The manipulation of the argument user_name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-207847.

CVE-2022-0941
star7th/showdoc Web
7.3
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-41567
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2022 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-4088
Stock Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214322 is the identifier assigned to this vulnerability.

CVE-2022-2674
Best Fee Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Best Fee Management System. It has been rated as critical. Affected by this issue is the function login of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205658 is the identifier assigned to this vulnerability.

CVE-2022-2079
nocodb/nocodb Web
7.3
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-2812
Guest Management System Web Database
7.3
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-206398 is the identifier assigned to this vulnerability.

CVE-2022-4805
usememos/memos Web
7.3
HIGH
EPSS
0.2%
2022 CWE-648 1 PoC

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1464
gogs/gogs Web
7.3
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .