7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37190
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 0 PoCs

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

CVE-2022-1764
WP-chgFontSize Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-31977
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.1%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVE-2022-43703
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-427 1 PoC

An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.

CVE-2022-1788
Change Uploaded File Permissions Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

CVE-2022-2537
WooCommerce PDF Invoices & Packing Slips Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

CVE-2022-31301
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.

CVE-2022-32092
Software Genérico General
N/A
UNKNOWN
EPSS
22.5%
2022 1 PoC

D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.

CVE-2022-30280
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests lik

CVE-2022-20142
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-216631962

CVE-2022-27295
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVE-2022-22834
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2022 1 PoC

An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.

CVE-2022-50798
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

Sin descripción disponible.

CVE-2022-41192
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-33885
utodesk® AutoCAD®, Advance Steel and Civil 3D® General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.

CVE-2022-2415
Chrome General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-43677
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.

CVE-2022-32118
Software Genérico Web
N/A
UNKNOWN
EPSS
5.0%
2022 1 PoC

Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.

CVE-2022-34295
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

totd before 1.5.3 does not properly randomize mesg IDs.

CVE-2022-2172
LinkWorth Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.