7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27881
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.

CVE-2022-32317
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at libvo/vo_v4l2.c. This vulnerability can lead to a Denial of Service (DoS) via a crafted file. The device=strdup statement is not executed on every call. Note: This has been disputed by third parties as invalid and not reproduceable.

CVE-2022-28480
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

CVE-2022-32248
SAP S/4HANA General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the data.

CVE-2022-35911
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string. NOTE: the vendor's perspective is that "omitting the query string does not cause a denial of service and the indicated event can not be reproduced.

CVE-2022-31201
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

SoftGuard Web (SGW) before 5.1.5 allows HTML injection.

CVE-2022-0164
Coming soon and Maintenance mode Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

CVE-2022-27666
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 3 PoCs

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

CVE-2022-2833
Blender General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Endless Infinite loop in Blender-thumnailing due to logical bugs.

CVE-2022-20004
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-179699767

CVE-2022-26235
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate executables and libraries that run as the elevated SYSTEM user on Windows.

CVE-2022-35582
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not disclosed in the documentation. Knowing the credentials, attackers can use this feature to gain uncontrolled access to the device and therefore are considered an undocumented possibility for remote control.

CVE-2022-30982
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.

CVE-2022-1095
Mihdan: No External Links Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3128
Donation Thermometer Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-23049
Exponent CMS Web
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.

CVE-2022-2170
Microsoft Advertising Universal Event Tracking (UET) Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-79 1 PoC

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

CVE-2022-4754
Easy Social Box / Page Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-1568
Team Members Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-25216
DVDFab 12 Player / PlayerFab Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.7%
2022 2 PoCs

An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.