7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36663
Software Genérico General
N/A
UNKNOWN
EPSS
16.4%
2022 1 PoC

Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.

CVE-2022-24396
SAP Focused Run (Simple Diagnostics Agent) Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-306 2 PoCs

The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.

CVE-2022-1274
keycloak General
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-80 2 PoCs

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

CVE-2022-37797
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

CVE-2022-3857
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-1780
LaTeX for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-20133
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-206807679

CVE-2022-24654
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2022 2 PoCs

Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.

CVE-2022-0346
XML Sitemap Generator for Google Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2022 CWE-79 1 PoC

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

CVE-2022-35170
SAP NetWeaver Enterprise Portal Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.

CVE-2022-1673
WooCommerce Green Wallet Gateway Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter before outputting it to the page, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2022-2657
Multivendor Marketplace Solution for WooCommerce – WC Marketplace Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF

CVE-2022-24236
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.

CVE-2022-22946
Spring Cloud Gateway Web Cloud
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

CVE-2022-24181
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2022 2 PoCs

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVE-2022-1829
Inline Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-33103
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().

CVE-2022-34094
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php.

CVE-2022-24341
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

CVE-2022-23377
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.