7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-31594
SAP Adaptive Server Enterprise (ASE) General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-269 1 PoC

A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.

CVE-2022-1557
ULeak Security & Monitoring Plugin Web Windows
N/A
UNKNOWN
EPSS
2.8%
2022 CWE-79 2 PoCs

The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks against admins viewing the settings

CVE-2022-32311
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.

CVE-2022-23878
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

CVE-2022-26306
LibreOffice General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-326 1 PoC

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVE-2022-30600
moodle General
N/A
UNKNOWN
EPSS
6.9%
2022 CWE-682 1 PoC

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVE-2022-24331
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

CVE-2022-1814
WP Admin Style Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVE-2022-37176
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

CVE-2022-31454
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books has a relationship to Yii 2.

CVE-2022-37177
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for multiple reasons, e.g., it is inconsistent with CVE ID assignment rules for cloud services, and no product with version V1.0 exists. Furthermore, the rail-fence cipher has been removed, and TLS 1.2 is now used for encryption.

CVE-2022-34169
Apache Xalan-J Web
N/A
UNKNOWN
EPSS
11.0%
2022 4 PoCs

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

CVE-2022-1779
Auto Delete Posts Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

CVE-2022-23072
recipes Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.

CVE-2022-28796
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

CVE-2022-1564
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-40146
Apache XML Graphics Web
N/A
UNKNOWN
EPSS
47.8%
2022 CWE-918 2 PoCs

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.

CVE-2022-36588
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.

CVE-2022-22541
SAP BusinessObjects Business Intelligence Platform General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-213 1 PoC

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access.

CVE-2022-29957
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.