3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3720
Event Monster Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

CVE-2022-43146
Software Genérico Web
7.2
HIGH
EPSS
0.9%
2022 2 PoCs

An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-1538
Theme Demo Import Web Windows
7.2
HIGH
EPSS
0.6%
2022 1 PoC

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.

CVE-2022-24899
contao Web ⚡ nuclei
7.2
HIGH
EPSS
44.0%
2022 CWE-79 0 PoCs

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

CVE-2022-4680
Revive Old Posts Web Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-3334
Easy WP SMTP Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-42279
NVIDIA DGX servers Web
7.2
HIGH
EPSS
0.6%
2022 CWE-78 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-3249
WP CSV Exporter Web Database Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks

CVE-2022-38066
QUARTZ-GOLD Web
7.2
HIGH
EPSS
0.4%
2022 CWE-78 2 PoCs

An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP response can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2022-4370
multimedial images Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2022-4355
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-38459
QUARTZ-GOLD Web
7.2
HIGH
EPSS
10.2%
2022 CWE-120 2 PoCs

A stack-based buffer overflow vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1243
medialize/uri.js Web
7.2
HIGH
EPSS
0.3%
2022 CWE-20 1 PoC

CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.

CVE-2022-3366
PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

CVE-2022-0970
getgrav/grav Web
7.1
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVE-2022-0956
star7th/showdoc Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

CVE-2022-35878
iota All-In-One Security Kit Web
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `ST` and `Location` HTTP response headers, as used within the `DoEnumUPnPService` action handler.

CVE-2022-0821
orchardcms/orchardcore Web
7.1
HIGH
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVE-2022-0253
livehelperchat/livehelperchat Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-31192
DSpace Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this vulnerability.