7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22819
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.

CVE-2022-35171
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 1 PoC

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVE-2022-28078
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2022 2 PoCs

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

CVE-2022-23345
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

CVE-2022-24237
Software Genérico General
N/A
UNKNOWN
EPSS
23.4%
2022 1 PoC

The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.

CVE-2022-0448
CP Blocks Web Windows
N/A
UNKNOWN
EPSS
6.3%
2022 CWE-79 1 PoC

The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-27665
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-side commands. For example, there is Client-Side Template Injection via subFolderPath to the ThinClient/WtmApiService.asmx/GetFileSubTree URI.

CVE-2022-23900
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.8%
2022 1 PoC

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

CVE-2022-0530
unzip General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

CVE-2022-29612
SAP NetWeaver, ABAP Platform and SAP Host Agent General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-918 1 PoC

SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.

CVE-2022-27043
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
25.5%
2022 0 PoCs

Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.

CVE-2022-32398
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

CVE-2022-26580
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2022-2083
Simple Single Sign On Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.

CVE-2022-41974
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVE-2022-34906
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

CVE-2022-41850
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.

CVE-2022-31324
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.

CVE-2022-0328
Simple Membership Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2022-39190
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.