7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-26034
CENTUM VP series with VP6E5000(AD Suite Engineering ServerFunction) installed and B/M9000 VP General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01 allows an attacker to use the functions provided by AD server. This may lead to leakage or tampering of data managed by AD server.

CVE-2022-1792
Quick Subscribe Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them

CVE-2022-2273
Simple Membership Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-269 1 PoC

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.

CVE-2022-26186
Software Genérico Networking
N/A
UNKNOWN
EPSS
23.8%
2022 1 PoC

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

CVE-2022-26173
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

CVE-2022-0649
AdRotate – Ad manager & AdSense Ads Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-46486
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

A lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attackers to access sensitive information.

CVE-2022-1020
Product Table for WooCommerce (wooproducttable) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2022 CWE-862 1 PoC

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

CVE-2022-2189
WP Video Lightbox Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2022-40764
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

CVE-2022-28805
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

CVE-2022-0211
Shield Security – Scanners, Security Hardening, Brute Force Protection & Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-2381
E Unlocked – Student Result Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack

CVE-2022-29733
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.

CVE-2022-44215
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2022 1 PoC

There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

CVE-2022-22845
Software Genérico General
N/A
UNKNOWN
EPSS
13.5%
2022 1 PoC

QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.

CVE-2022-35016
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Advancecomp v2.3 was discovered to contain a heap buffer overflow.

CVE-2022-32985
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

CVE-2022-1165
Blackhole for Bad Bots Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-639 1 PoC

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.

CVE-2022-2239
Request a Quote Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.