3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-32510
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-0961
microweber/microweber Web
7.1
HIGH
EPSS
1.8%
2022 CWE-190 1 PoC

The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-20822
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.5%
2022 CWE-22 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to. Cisco plans to release softw

CVE-2022-4692
usememos/memos Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-0378
microweber/microweber Web ⚡ nuclei
7.1
HIGH
EPSS
7.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-31647
Software Genérico DevOps Web Windows
7.1
HIGH
EPSS
0.0%
2022 1 PoC

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.

CVE-2022-45836
Download Manager Web ⚡ nuclei
7.1
HIGH
EPSS
8.0%
2022 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

CVE-2022-31192
DSpace Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2022-1452
radareorg/radare2 Web
7.1
HIGH
EPSS
0.3%
2022 CWE-125 2 PoCs

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

CVE-2022-4690
usememos/memos Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-1451
radareorg/radare2 Web
7.1
HIGH
EPSS
0.3%
2022 CWE-788 2 PoCs

Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

CVE-2022-0926
microweber/microweber Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-2066
neorazorx/facturascripts Web
7.1
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06.

CVE-2022-45365
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
20.1%
2022 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

CVE-2022-20956
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.3%
2022 CWE-648 3 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vul

CVE-2022-1400
CMDB Web
7.1
HIGH
EPSS
0.4%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.

CVE-2022-2924
yetiforcecompany/yetiforcecrm Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

CVE-2022-0821
orchardcms/orchardcore Web
7.1
HIGH
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVE-2022-21593
HTTP Server Web Database
7.1
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data as well as unauthorized update, insert or delete access to

CVE-2022-25760
accesslog Web
7.1
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible for an attacker to execute arbitrary JavaScript code on the host that this package is being run on.