7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36173
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service.

CVE-2022-32086
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVE-2022-32409
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
66.5%
2022 1 PoC

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

CVE-2022-2639
kernel General
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-192 5 PoCs

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVE-2022-4023
3dprint Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will create an archive of any files or directories on the target server by tricking a logged in admin into submitting a form. Furthermore the created archive has a predictable location and name, allowing the attacker to download the file if they know the time at which the form was submitted, making it possible to leak sensitive files like the WordPress configuration containing database cre

CVE-2022-0867
Pricing Table Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2022 CWE-89 1 PoC

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

CVE-2022-3218
WiFi Mouse (Mouse Server) General
N/A
UNKNOWN
EPSS
84.6%
2022 CWE-603 3 PoCs

Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.

CVE-2022-28079
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2022 2 PoCs

College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.

CVE-2022-28960
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

CVE-2022-35585
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parameter

CVE-2022-1192
Turn off all comments Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 2 PoCs

The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-35416
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2022 1 PoC

H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

CVE-2022-26633
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.

CVE-2022-1167
Careerup Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.

CVE-2022-0830
FormBuilder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.

CVE-2022-0874
WP Social Buttons Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-29610
SAP NetWeaver Application Server ABAP Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

CVE-2022-25004
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.

CVE-2022-39810
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.