7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1295
alvarotrigo/fullpage.js General
7.3
HIGH
EPSS
0.6%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.

CVE-2022-2467
Garage Management System Web Database ⚡ nuclei
7.3
HIGH
EPSS
71.9%
2022 CWE-89 0 PoCs

A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-39858
FactoryCamera General
7.3
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.

CVE-2022-3368
"Avira Security" – for Windows Windows
7.3
HIGH
EPSS
3.1%
2022 2 PoCs

A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.

CVE-2022-41567
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2022 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-26671
Personnel Attendance Management system General
7.3
HIGH
EPSS
0.6%
2022 CWE-798 1 PoC

Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

CVE-2022-1083
Microfinance Management System Database
7.3
HIGH
EPSS
0.4%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc leads to sql injection in multiple files. It is possible to launch the attack remotely.

CVE-2022-28194
Jetson AGX Xavier series, Jetson Xavier NX General
7.3
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-1160
vim/vim General
7.3
HIGH
EPSS
0.6%
2022 CWE-122 1 PoC

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

CVE-2022-4088
Stock Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214322 is the identifier assigned to this vulnerability.

CVE-2022-1084
One Church Management System Web
7.3
HIGH
EPSS
0.4%
2022 CWE-287 1 PoC

A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched remotely.

CVE-2022-21516
Enterprise Manager Base Platform Web Database
7.3
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data an

CVE-2022-1061
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-122 1 PoC

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

CVE-2022-4805
usememos/memos Web
7.3
HIGH
EPSS
0.2%
2022 CWE-648 1 PoC

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-32543
Alyac General
7.3
HIGH
EPSS
0.2%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-21803
nconf General
7.3
HIGH
EPSS
0.9%
2022 2 PoCs

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

CVE-2022-1464
gogs/gogs Web
7.3
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .

CVE-2022-1785
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

CVE-2022-0845
pytorchlightning/pytorch-lightning General
7.3
HIGH
EPSS
0.3%
2022 CWE-94 1 PoC

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

CVE-2022-2842
Gym Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-206451.