7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-35191
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVE-2022-34049
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
15.5%
2022 1 PoC

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

CVE-2022-29962
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

CVE-2022-1103
Advanced uploader Web Windows
N/A
UNKNOWN
EPSS
16.6%
2022 CWE-434 1 PoC

The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

CVE-2022-34618
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.

CVE-2022-1939
Allow svg files Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-434 1 PoC

The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to

CVE-2022-29013
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2022 2 PoCs

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2022-0656
Web To Print Shop : uDraw Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2022 CWE-552 1 PoC

The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

CVE-2022-27174
Easy Blog for EC-CUBE4 Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page.

CVE-2022-1828
PDF24 Articles To PDF Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-38794
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2022 1 PoC

Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.

CVE-2022-26250
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.

CVE-2022-38844
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.

CVE-2022-24562
Software Genérico General
N/A
UNKNOWN
EPSS
49.2%
2022 3 PoCs

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

CVE-2022-26293
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2022 3 PoCs

Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.

CVE-2022-2116
Contact Form DB – Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

CVE-2022-38256
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-23824
AMD Processors General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

CVE-2022-36523
Software Genérico Web
N/A
UNKNOWN
EPSS
5.1%
2022 1 PoC

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

CVE-2022-32115
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.