7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4199
Link Library Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3618
Spacer Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-29837
My Cloud Home Cloud
4.7
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

CVE-2022-46091
Software Genérico Web
4.7
MEDIUM
EPSS
0.2%
2022 1 PoC

Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.

CVE-2022-1837
Home Clean Services Management System Web
4.7
MEDIUM
EPSS
1.1%
2022 CWE-434 1 PoC

A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.

CVE-2022-2250
GitLab DevOps
4.7
MEDIUM
EPSS
0.3%
2022 1 PoC

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2022-29475
iota All-In-One Security Kit General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-294 1 PoC

An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2022-2546
All-in-One WP Migration Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
16.2%
2022 5 PoCs

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

CVE-2022-4402
DocSys General
4.7
MEDIUM
EPSS
0.8%
2022 CWE-22 1 PoC

A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.

CVE-2022-1838
Home Clean Services Management System Web Database
4.7
MEDIUM
EPSS
0.4%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

CVE-2022-0692
rudloff/alltube General ⚡ nuclei
4.7
MEDIUM
EPSS
20.8%
2022 CWE-601 1 PoC

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

CVE-2022-3549
Simple Cold Storage Management System General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-266 1 PoC

A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211049 was assigned to this vulnerability.

CVE-2022-3750
Ask me Web
4.7
MEDIUM
EPSS
0.2%
2022 1 PoC

The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.

CVE-2022-21368
MySQL Server Database
4.7
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL

CVE-2022-0239
stanfordnlp/corenlp General
4.7
MEDIUM
EPSS
0.0%
2022 CWE-611 1 PoC

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2022-2018
Prison Management System Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The manipulation of the argument id with the input 1%27%20and%201=2%20union%20select%201,user(),3,4,5,6,7,8,9,0,database(),2,3,4,5,6,7,8,9,0,1,2,3,4--+ leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-29800
networkd-dispatcher General
4.7
MEDIUM
EPSS
0.1%
2022 CWE-367 1 PoC

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVE-2022-2262
Online Hotel Booking System Web Database
4.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input 2828%27%20AND%20(SELECT%203766%20FROM%20(SELECT(SLEEP(5)))BmIK)%20AND%20%27YLPl%27=%27YLPl leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-1384
Mattermost General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-477 1 PoC

Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.

CVE-2022-4282
SpringBootCMS Web
4.7
MEDIUM
EPSS
0.4%
2022 CWE-707 1 PoC

A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214790 is the identifier assigned to this vulnerability.