7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45362
Paytm Payment Gateway General ⚡ nuclei
7.2
HIGH
EPSS
32.9%
2022 CWE-918 0 PoCs

Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.

CVE-2022-3608
thorsten/phpmyfaq Web
7.2
HIGH
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

CVE-2022-41016
QUARTZ-GOLD Networking
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no vpn basic protocol (l2tp|pptp) name WORD server WORD username WORD passsword WORD firmwall (on|off) defroute (on|off)' command template.

CVE-2022-50894
VIAVIWEB Wallpaper Admin Web Database
7.1
HIGH
EPSS
0.0%
2022 CWE-89 1 PoC

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

CVE-2022-35879
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `controlURL` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-0956
star7th/showdoc Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

CVE-2022-20822
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.5%
2022 CWE-22 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to. Cisco plans to release softw

CVE-2022-20956
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.3%
2022 CWE-648 3 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vul

CVE-2022-42280
NVIDIA DGX servers General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

CVE-2022-4294
Norton Antivirus Windows Eraser Engine Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2022-21278
MySQL Server Database
7.1
HIGH
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVS

CVE-2022-0436
gruntjs/grunt General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

CVE-2022-21544
FLEXCUBE Universal Banking Web Database
7.1
HIGH
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availabi

CVE-2022-0896
microweber/microweber General
7.1
HIGH
EPSS
1.0%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-42855
tvOS General
7.1
HIGH
EPSS
0.1%
2022 6 PoCs

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

CVE-2022-33926
Wyse Management Suite General
7.1
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.

CVE-2022-21351
MySQL Server Database
7.1
HIGH
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVS

CVE-2022-28753
Zoom On-Premise Meeting Connector MMR General
7.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-0144
shelljs/shelljs General
7.1
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

shelljs is vulnerable to Improper Privilege Management

CVE-2022-50799
Fetch Softworks Fetch FTP Client General
7.1
HIGH
EPSS
0.1%
2022 CWE-770 2 PoCs

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application.