5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4197
Sliderby10Web Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Sliderby10Web WordPress plugin before 1.2.53 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-44213
Software Genérico Web Cloud
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-3750
Ask me Web
4.7
MEDIUM
EPSS
0.2%
2022 1 PoC

The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.

CVE-2022-4282
SpringBootCMS Web
4.7
MEDIUM
EPSS
0.4%
2022 CWE-707 1 PoC

A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214790 is the identifier assigned to this vulnerability.

CVE-2022-31238
PowerScale OneFS General
4.7
MEDIUM
EPSS
0.1%
2022 1 PoC

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this vulnerability, leading to information disclosure.

CVE-2022-46091
Software Genérico Web
4.7
MEDIUM
EPSS
0.2%
2022 1 PoC

Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.

CVE-2022-1837
Home Clean Services Management System Web
4.7
MEDIUM
EPSS
1.1%
2022 CWE-434 1 PoC

A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.

CVE-2022-29475
iota All-In-One Security Kit General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-294 1 PoC

An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2022-21469
Enterprise Manager Base Platform Web Database
4.7
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in u

CVE-2022-1838
Home Clean Services Management System Web Database
4.7
MEDIUM
EPSS
0.4%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

CVE-2022-21368
MySQL Server Database
4.7
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL

CVE-2022-0239
stanfordnlp/corenlp General
4.7
MEDIUM
EPSS
0.0%
2022 CWE-611 1 PoC

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2022-2263
Online Hotel Booking System Web Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit_room_cat.php of the component Room Handler. The manipulation of the argument roomname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-2017
Prison Management System Web Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/view_visit.php of the component Visit Handler. The manipulation of the argument id with the input 2%27and%201=2%20union%20select%201,2,3,4,5,6,7,user(),database()--+ leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-34704
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
3.3%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-4052
Student Attendance Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213845 was assigned to this vulnerability.

CVE-2022-3486
GitLab DevOps
4.7
MEDIUM
EPSS
0.4%
2022 2 PoCs

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2022-41215
SAP NetWeaver ABAP Server and ABAP Platform General
4.7
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.

CVE-2022-29837
My Cloud Home Cloud
4.7
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.