3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-2711
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-22 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

CVE-2022-4370
multimedial images Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2022-38459
QUARTZ-GOLD Web
7.2
HIGH
EPSS
10.2%
2022 CWE-120 2 PoCs

A stack-based buffer overflow vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-43970
WRT54GL Wireless-G Broadband Router Web Networking
7.2
HIGH
EPSS
4.0%
2022 CWE-120 3 PoCs

A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux operating system as root. This vulnerablity can be triggered over the network via a malicious POST request to /apply.cgi.

CVE-2022-40220
QUARTZ-GOLD Web
7.2
HIGH
EPSS
2.4%
2022 CWE-78 2 PoCs

An OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-3418
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
1.4%
2022 CWE-94 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files

CVE-2022-3335
Kadence WooCommerce Email Designer Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-3249
WP CSV Exporter Web Database Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks

CVE-2022-3490
Checkout Field Editor (Checkout Manager) for WooCommerce Web Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

CVE-2022-4324
Custom Field Template Web Windows
7.2
HIGH
EPSS
1.2%
2022 1 PoC

The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

CVE-2022-42278
NVIDIA DGX servers Web
7.2
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-31109
laminas-diactoros Web
7.2
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a `Laminas\Diactoros\Uri` instance associated with the incoming server request modified to reflect values from `X-Forwarded-*` headers. Such changes can potentially lead to XSS attacks (if a fully-qualified URL is used in links) and/or URL poisoning. Since the `X-Forwarded-*` headers do hav

CVE-2022-39179
College Management System v1.0 Web Database
7.2
HIGH
EPSS
1.4%
2022 1 PoC

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

CVE-2022-39045
QUARTZ-GOLD Web
7.2
HIGH
EPSS
3.3%
2022 CWE-22 2 PoCs

A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1429
pimcore/pimcore Web Database
7.2
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data

CVE-2022-0968
microweber/microweber Web ⚡ nuclei
7.2
HIGH
EPSS
1.4%
2022 CWE-190 1 PoC

The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-3925
buddybadges Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-3608
thorsten/phpmyfaq Web
7.2
HIGH
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

CVE-2022-3302
Spam protection, AntiSpam, FireWall by CleanTalk Web Networking Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin

CVE-2022-36279
QUARTZ-GOLD Web
7.2
HIGH
EPSS
8.9%
2022 CWE-120 2 PoCs

A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.