5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2633
All-in-One Video Gallery Web Windows ⚡ nuclei
7.5
HIGH
EPSS
88.4%
2022 0 PoCs

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

CVE-2022-42276
NVIDIA DGX servers General
7.5
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-22144
LinkHub Mesh Wifi General
7.5
HIGH
EPSS
0.4%
2022 CWE-259 1 PoC

A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do anything to trigger this vulnerability.

CVE-2022-21300
PeopleSoft Enterprise CS SA Integration Pack Web Database
7.5
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Snapshot Integration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS SA Integration Pack. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS SA Integration Pack accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:

CVE-2022-41649
OpenImageIO General
7.5
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted TIFF file can cause a read of adjacent heap memory, which can leak sensitive process information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-42732
syngo Dynamics General
7.5
HIGH
EPSS
0.3%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.

CVE-2022-4106
Wholesale Market for WooCommerce Web Windows
7.5
HIGH
EPSS
1.2%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVE-2022-21952
SUSE Manager Server 4.1 General
7.5
HIGH
EPSS
0.4%
2022 CWE-306 1 PoC

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.

CVE-2022-39812
Software Genérico General
7.5
HIGH
EPSS
1.2%
2022 1 PoC

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary directory. Because the application does not check in which directory a file will be uploaded, an attacker can perform a variety of attacks that can result in unauthorized access to the server.

CVE-2022-34127
Software Genérico Web
7.5
HIGH
EPSS
17.9%
2022 1 PoC

The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.

CVE-2022-42123
Software Genérico Database
7.5
HIGH
EPSS
0.4%
2022 1 PoC

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.

CVE-2022-4061
JobBoardWP Web Windows
7.5
HIGH
EPSS
25.0%
2022 1 PoC

The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.

CVE-2022-47076
Software Genérico General
7.5
HIGH
EPSS
23.4%
2022 3 PoCs

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.

CVE-2022-0236
WP Import Export Web Windows
7.5
HIGH
EPSS
37.4%
2022 CWE-862 2 PoCs

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

CVE-2022-43140
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
40.0%
2022 0 PoCs

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.

CVE-2022-25314
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

CVE-2022-31414
Software Genérico Web
7.5
HIGH
EPSS
0.7%
2022 1 PoC

D-Link DIR-1960 firmware DIR-1960_A1_1.11 was discovered to contain a buffer overflow via srtcat in prog.cgi. This vulnerability allowed attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVE-2022-34830
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 2 PoCs

An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GPU processing operations to gain access to already freed memory.

CVE-2022-27169
OAS Platform General
7.5
HIGH
EPSS
0.8%
2022 CWE-306 1 PoC

An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.

CVE-2022-43343
Software Genérico General
7.5
HIGH
EPSS
4.1%
2022 1 PoC

N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c.