7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4782
ClickFunnels Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-32013
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.

CVE-2022-31200
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field.

CVE-2022-30067
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

CVE-2022-36449
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2022 5 PoCs

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory, write a limited amount outside of buffer bounds, or to disclose details of memory mappings. This affects Midgard r4p0 through r32p0, Bifrost r0p0 through r38p0 and r39p0 before r38p1, and Valhall r19p0 through r38p0 and r39p0 before r38p1.

CVE-2022-1967
WP Championship Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-1217
Custom TinyMCE Shortcode Button Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.

CVE-2022-28005
Software Genérico Windows
N/A
UNKNOWN
EPSS
24.8%
2022 2 PoCs

An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. NOTE: this issue exists because of an incomplete fix for

CVE-2022-0442
UsersWP – User Registration & User Profile Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

CVE-2022-27456
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

CVE-2022-27092
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-2798
Affiliates Manager Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-1236 1 PoC

The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data

CVE-2022-1542
hpb Dashboard Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-31861
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

CVE-2022-42889
Apache Commons Text Web
N/A
UNKNOWN
EPSS
94.3%
2022 45 PoCs

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dn

CVE-2022-2184
CAPTCHA 4WP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-22 1 PoC

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

CVE-2022-27907
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

CVE-2022-1932
Rezgo Online Booking Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file

CVE-2022-39188
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries. This only occurs in situations with VM_PFNMAP VMAs.

CVE-2022-34970
Software Genérico General
N/A
UNKNOWN
EPSS
24.0%
2022 2 PoCs

Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.