2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30575
TIBCO Data Science - Workbench Web
7.3
HIGH
EPSS
0.6%
2022 1 PoC

The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO

CVE-2022-3664
Bento4 General
7.3
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

CVE-2022-3060
GitLab DevOps
7.3
HIGH
EPSS
0.4%
2022 1 PoC

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVE-2022-21658
rust General
7.3
HIGH
EPSS
0.9%
2022 CWE-363 1 PoC

Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't

CVE-2022-21516
Enterprise Manager Base Platform Web Database
7.3
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data an

CVE-2022-0845
pytorchlightning/pytorch-lightning General
7.3
HIGH
EPSS
0.3%
2022 CWE-94 1 PoC

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

CVE-2022-2802
Gas Agency Management System Web Database
7.3
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206248.

CVE-2022-41567
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2022 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-36833
Game Optimizing Service General
7.3
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.

CVE-2022-2664
Private Cloud Management Platform Web Cloud
7.3
HIGH
EPSS
0.3%
2022 CWE-287 1 PoC

A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. VDB-205614 is the identifier assigned to this vulnerability.

CVE-2022-1083
Microfinance Management System Database
7.3
HIGH
EPSS
0.4%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc leads to sql injection in multiple files. It is possible to launch the attack remotely.

CVE-2022-26671
Personnel Attendance Management system General
7.3
HIGH
EPSS
0.6%
2022 CWE-798 1 PoC

Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

CVE-2022-1160
vim/vim General
7.3
HIGH
EPSS
0.6%
2022 CWE-122 1 PoC

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

CVE-2022-0265
hazelcast/hazelcast General
7.3
HIGH
EPSS
8.3%
2022 CWE-611 2 PoCs

Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

CVE-2022-30755
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

CVE-2022-45101
PowerScale OneFS General
7.3
HIGH
EPSS
4.2%
2022 CWE-274 1 PoC

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution.

CVE-2022-2467
Garage Management System Web Database ⚡ nuclei
7.3
HIGH
EPSS
71.9%
2022 CWE-89 0 PoCs

A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-4088
Stock Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214322 is the identifier assigned to this vulnerability.

CVE-2022-4805
usememos/memos Web
7.3
HIGH
EPSS
0.2%
2022 CWE-648 1 PoC

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-2812
Guest Management System Web Database
7.3
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-206398 is the identifier assigned to this vulnerability.