7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-23120
Trend Micro Deep Security Agent for Linux Cloud
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.

CVE-2022-28217
SAP NetWeaver (EP Web Page Composer) General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-918 1 PoC

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.

CVE-2022-29729
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVE-2022-37123
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.

CVE-2022-2269
Website File Changes Monitor Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-89 1 PoC

The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection

CVE-2022-34527
Software Genérico General
N/A
UNKNOWN
EPSS
24.9%
2022 2 PoCs

D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160.

CVE-2022-1644
Call&Book Mobile Bar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-30328
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.

CVE-2022-2599
Anti-Malware Security and Brute-Force Firewall Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
30.9%
2022 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-34960
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.

CVE-2022-1591
WordPress Ping Optimizer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-29866
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

CVE-2022-28329
SCALANCE W1788-1 M12 General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 1 PoC

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed TCP packets received over the RemoteCapture feature. This could allow an attacker to lead to a denial of service condition which only affects the port used by the RemoteCapture feature.

CVE-2022-2115
Popup Anything – A Marketing Popup and Lead Generation Conversions Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting

CVE-2022-25166
Software Genérico Networking Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

CVE-2022-28986
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2022 1 PoC

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.

CVE-2022-27255
Software Genérico General
N/A
UNKNOWN
EPSS
15.2%
2022 2 PoCs

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.

CVE-2022-37700
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2022 2 PoCs

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.

CVE-2022-37232
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

CVE-2022-30105
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2022 1 PoC

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.