7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22531
SAP S/4HANA General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed or modified.

CVE-2022-30512
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.8%
2022 2 PoCs

School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.

CVE-2022-0418
Event List Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed

CVE-2022-26281
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

CVE-2022-0420
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-89 1 PoC

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

CVE-2022-23342
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.

CVE-2022-25497
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

CVE-2022-35206
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.

CVE-2022-29582
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 5 PoCs

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

CVE-2022-29775
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.9%
2022 0 PoCs

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

CVE-2022-24954
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.

CVE-2022-43403
Jenkins Script Security Plugin DevOps
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVE-2022-48554
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

CVE-2022-2737
WP STAGING – Backup Duplicator & Migration Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0229
miniOrange's Google Authenticator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

CVE-2022-0770
Translate WordPress with GTranslate Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-352 1 PoC

The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

CVE-2022-29360
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.

CVE-2022-1392
Videos sync PDF Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2022 CWE-22 2 PoCs

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

CVE-2022-27223
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.

CVE-2022-24976
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.