7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3021
Slickr Flickr Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Slickr Flickr WordPress plugin through 2.8.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3132
Goolytics – Simple Google Analytics Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-31496
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.

CVE-2022-0205
YOP Poll Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

CVE-2022-31373
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2022 0 PoCs

SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.

CVE-2022-24449
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

CVE-2022-26744
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

CVE-2022-0952
Sitemap by click5 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2022 2 PoCs

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

CVE-2022-29854
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 3 PoCs

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVE-2022-26565
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.

CVE-2022-3220
Advanced Comment Form Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-29023
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A buffer overflow vulnerability exists in the razermouse driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of Service (DoS) and possibly escalate their privileges via a crafted buffer sent to the matrix_custom_frame device.

CVE-2022-29865
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 2 PoCs

OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

CVE-2022-29864
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

CVE-2022-2839
Zephyr Project Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

CVE-2022-25331
Trend Micro ServerProtect for Storage General
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process.

CVE-2022-23332
Software Genérico General
N/A
UNKNOWN
EPSS
12.8%
2022 1 PoC

Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.

CVE-2022-3182
Remote Desktop Manager General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-284 1 PoC

Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.

CVE-2022-2840
Zephyr Project Manager Web Database Windows
N/A
UNKNOWN
EPSS
3.8%
2022 CWE-89 2 PoCs

The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections

CVE-2022-25762
Apache Tomcat Web
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-404 1 PoC

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.