7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24578
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

CVE-2022-24405
Software Genérico Web
N/A
UNKNOWN
EPSS
8.0%
2022 1 PoC

OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

CVE-2022-47673
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts.

CVE-2022-28214
SAP BusinessObjects Enterprise (Central Management Server) Web
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-312 1 PoC

During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and Availability.

CVE-2022-2538
WP Hide & Security Enhancer Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting

CVE-2022-1251
Ask me Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

CVE-2022-1970
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-36620
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

CVE-2022-25220
PeTeReport Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding.

CVE-2022-1386
Fusion Builder Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 CWE-918 9 PoCs

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVE-2022-24252
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2022 1 PoC

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

CVE-2022-4386
Intuitive Custom Post Order Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack

CVE-2022-29651
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-35069
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e.

CVE-2022-48064
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

CVE-2022-20229
Android General
N/A
UNKNOWN
EPSS
12.5%
2022 1 PoC

In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224536184

CVE-2022-32173
OrchardCore General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.

CVE-2022-0674
Kunze Law Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-26629
Software Genérico General
N/A
UNKNOWN
EPSS
30.5%
2022 2 PoCs

An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

CVE-2022-30783
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.