7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-34101
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.

CVE-2022-29301
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-32391
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

CVE-2022-31298
Software Genérico Web
N/A
UNKNOWN
EPSS
7.5%
2022 1 PoC

A cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

CVE-2022-1301
WP Contact Slider Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2022-1194
Mobile Events Manager Web Windows
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-1236 1 PoC

The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

CVE-2022-27904
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.

CVE-2022-28991
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

CVE-2022-31245
Software Genérico General
N/A
UNKNOWN
EPSS
25.1%
2022 1 PoC

mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.

CVE-2022-27944
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.

CVE-2022-36633
Software Genérico Networking
N/A
UNKNOWN
EPSS
30.3%
2022 2 PoCs

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

CVE-2022-1627
My Private Site Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-34328
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.0%
2022 0 PoCs

PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

CVE-2022-31262
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 4 PoCs

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.

CVE-2022-0785
Daily Prayer Time Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.3%
2022 CWE-89 1 PoC

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-2458
Red Hat Process Automation Manager 7 General
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-91 1 PoC

XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction & Internal file read in Business Central and also

CVE-2022-26377
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
38.7%
2022 CWE-444 1 PoC

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.

CVE-2022-23968
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later vers

CVE-2022-35890
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.

CVE-2022-1580
Site Offline Or Coming Soon Or Maintenance Mode Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.0%
2022 CWE-639 1 PoC

The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.