5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4015
Sports Club Management System Web Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unknown part of the file admin/make_payments.php. The manipulation of the argument m_id/plan leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213789 was assigned to this vulnerability.

CVE-2022-3303
Linux kernel General
4.7
MEDIUM
EPSS
0.0%
2022 CWE-667 1 PoC

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition

CVE-2022-4732
microweber/microweber General
4.7
MEDIUM
EPSS
1.1%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-49633
Linux General
4.7
MEDIUM
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: icmp: Fix data-races around sysctl_icmp_echo_enable_probe. While reading sysctl_icmp_echo_enable_probe, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

CVE-2022-3549
Simple Cold Storage Management System General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-266 1 PoC

A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211049 was assigned to this vulnerability.

CVE-2022-2546
All-in-One WP Migration Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
16.2%
2022 5 PoCs

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

CVE-2022-2250
GitLab DevOps
4.7
MEDIUM
EPSS
0.3%
2022 1 PoC

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2022-2262
Online Hotel Booking System Web Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input 2828%27%20AND%20(SELECT%203766%20FROM%20(SELECT(SLEEP(5)))BmIK)%20AND%20%27YLPl%27=%27YLPl leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-2018
Prison Management System Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The manipulation of the argument id with the input 1%27%20and%201=2%20union%20select%201,user(),3,4,5,6,7,8,9,0,database(),2,3,4,5,6,7,8,9,0,1,2,3,4--+ leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-1384
Mattermost General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-477 1 PoC

Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.

CVE-2022-29800
networkd-dispatcher General
4.7
MEDIUM
EPSS
0.1%
2022 CWE-367 1 PoC

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVE-2022-4402
DocSys General
4.7
MEDIUM
EPSS
0.8%
2022 CWE-22 1 PoC

A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.

CVE-2022-0692
rudloff/alltube General ⚡ nuclei
4.7
MEDIUM
EPSS
20.8%
2022 CWE-601 1 PoC

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

CVE-2022-0743
getgrav/grav Web
4.6
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVE-2022-2997
snipe/snipe-it General
4.6
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.

CVE-2022-1893
polonel/trudesk General
4.6
MEDIUM
EPSS
0.3%
2022 CWE-212 1 PoC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-39900
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.

CVE-2022-25873
vuetify Web
4.6
MEDIUM
EPSS
0.6%
2022 3 PoCs

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.

CVE-2022-30769
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2022 2 PoCs

Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.

CVE-2022-30730
Samsung Pass General
4.6
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.