5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4088
Stock Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214322 is the identifier assigned to this vulnerability.

CVE-2022-41567
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2022 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-21658
rust General
7.3
HIGH
EPSS
0.9%
2022 CWE-363 1 PoC

Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't

CVE-2022-21797
joblib General
7.3
HIGH
EPSS
0.3%
2022 1 PoC

The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

CVE-2022-3667
Bento4 General
7.3
HIGH
EPSS
0.6%
2022 CWE-119 1 PoC

A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212007.

CVE-2022-4302
White Label CMS Web Windows
7.2
HIGH
EPSS
1.2%
2022 1 PoC

The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-40924
Software Genérico General
7.2
HIGH
EPSS
0.4%
2022 1 PoC

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.

CVE-2022-43146
Software Genérico Web
7.2
HIGH
EPSS
0.9%
2022 2 PoCs

An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-41002
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null)' command template.

CVE-2022-40992
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no firmwall domain WORD description (WORD|null)' command template.

CVE-2022-41000
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no gre index <1-8> tunnel A.B.C.D source (A.B.C.D|null) dest A.B.C.D keepalive (on|off) interval (<0-255>|null) retry (<0-255>|null) description (WORD|null)' command template.

CVE-2022-23544
metersphere Web ⚡ nuclei
7.2
HIGH
EPSS
23.6%
2022 CWE-918 0 PoCs

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.

CVE-2022-4043
WP Custom Admin Interface Web Windows
7.2
HIGH
EPSS
1.2%
2022 1 PoC

The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-42201
Software Genérico General
7.2
HIGH
EPSS
0.4%
2022 1 PoC

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

CVE-2022-40969
QUARTZ-GOLD Web
7.2
HIGH
EPSS
1.8%
2022 CWE-78 2 PoCs

An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-3394
WP All Export Pro Web Windows
7.2
HIGH
EPSS
1.3%
2022 CWE-94 1 PoC

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVE-2022-1033
crater-invoice/crater General
7.2
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

CVE-2022-4372
Web Invoice Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well