7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38604
Software Genérico Windows
7.3
HIGH
EPSS
4.9%
2022 2 PoCs

Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.

CVE-2022-0849
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-0083
livehelperchat/livehelperchat General
7.3
HIGH
EPSS
0.2%
2022 CWE-209 1 PoC

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

CVE-2022-3766
thorsten/phpmyfaq Web ⚡ nuclei
7.3
HIGH
EPSS
18.6%
2022 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE-2022-1785
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

CVE-2022-3495
Simple Online Public Access Catalog Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210784.

CVE-2022-4141
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVE-2022-3878
ERP Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213039.

CVE-2022-2812
Guest Management System Web Database
7.3
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-206398 is the identifier assigned to this vulnerability.

CVE-2022-2019
Prison Management System Web
7.3
HIGH
EPSS
0.2%
2022 CWE-285 1 PoC

A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php?f=save of the component New User Creation. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-0839
liquibase/liquibase General
7.3
HIGH
EPSS
0.2%
2022 CWE-611 3 PoCs

Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

CVE-2022-2298
Clinics Patient Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument user_name with the input admin' or '1'='1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-3423
nocodb/nocodb General
7.3
HIGH
EPSS
1.1%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

CVE-2022-21658
rust General
7.3
HIGH
EPSS
0.9%
2022 CWE-363 1 PoC

Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't

CVE-2022-0265
hazelcast/hazelcast General
7.3
HIGH
EPSS
8.3%
2022 CWE-611 2 PoCs

Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

CVE-2022-23000
My Cloud Web Networking Cloud
7.3
HIGH
EPSS
0.1%
2022 CWE-757 2 PoCs

The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was enabled to maintain compatibility with old or outdated home routers. By using an "SSL" context instead of "TLS" or specifying stronger validation, deprecated or insecure protocols are permitted. As a result, a local user with no privileges can exploit this vulnerability and jeopardize the integrity, confidentiality and authenticity of information transmitted. The scope of impact cannot extend to other components and no user input is required to exp

CVE-2022-29886
Alyac General
7.3
HIGH
EPSS
0.1%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-41567
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2022 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-2664
Private Cloud Management Platform Web Cloud
7.3
HIGH
EPSS
0.3%
2022 CWE-287 1 PoC

A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. VDB-205614 is the identifier assigned to this vulnerability.

CVE-2022-0476
radareorg/radare2 General
7.3
HIGH
EPSS
0.2%
2022 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.