3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-25226
ThinVNC Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2022 3 PoCs

ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.

CVE-2022-26233
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.0%
2022 2 PoCs

Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

CVE-2022-27985
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-48165
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 0 PoCs

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2022-0949
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
62.5%
2022 CWE-89 1 PoC

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection

CVE-2022-31854
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 3 PoCs

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

CVE-2022-28032
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.7%
2022 0 PoCs

AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php

CVE-2022-31299
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.0%
2022 1 PoC

Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.

CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-25061
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2022 1 PoC

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

CVE-2022-0773
Documentor – Create Product Documentation Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.5%
2022 CWE-89 1 PoC

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

CVE-2022-38322
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-28508
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.

CVE-2022-29078
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2022 6 PoCs

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

CVE-2022-2383
Feed Them Social – for Twitter feed, Youtube and more Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.4%
2022 CWE-79 1 PoC

The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-47002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.0%
2022 0 PoCs

A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

CVE-2022-0827
Bestbooks Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.0%
2022 CWE-89 1 PoC

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-2187
Contact Form 7 Captcha Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2022 CWE-79 1 PoC

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2022-31845
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
53.1%
2022 0 PoCs

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.