7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0200
Themify Portfolio Post Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

CVE-2022-31260
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
24.8%
2022 0 PoCs

In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.

CVE-2022-41180
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-0647
Bulk Creator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-35296
SAP BusinessObjects Business Intelligence Platform (Version Management System) General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-200 1 PoC

Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.

CVE-2022-40010
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.

CVE-2022-38131
RStudio Connect General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2022 1 PoC

RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.

CVE-2022-22969
Spring Security OAuth Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.

CVE-2022-32026
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.

CVE-2022-22733
Apache ShardingSphere ElasticJob-UI Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.

CVE-2022-27671
SAP BusinessObjects Business Intelligence Platform Web
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-201 1 PoC

A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.

CVE-2022-48332
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant buffer overflow.

CVE-2022-1013
Personal Dictionary Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2022 CWE-89 1 PoC

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

CVE-2022-1549
WP Athletics Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.

CVE-2022-2409
Rough Chart Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Rough Chart WordPress plugin through 1.0.0 does not properly escape chart data label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-32430
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.9%
2022 0 PoCs

An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

CVE-2022-22547
Simple Diagnostics Agent General
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-200 1 PoC

Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a random port 9000-65535. This allows information gathering which could be used exploit future open-source security exploits.

CVE-2022-39832
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVE-2022-29603
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A remote authenticated attacker could send crafted SQL statements to a vulnerable endpoint (such as /api/students/me/messages/) to, for example, retrieve personal information or change grades.

CVE-2022-0598
Login with phone number Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.