7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27094
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-31464
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.

CVE-2022-1182
Visual Slide Box Builder Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections

CVE-2022-1436
WPCargo Track & Trace DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.

CVE-2022-29298
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 1 PoC

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

CVE-2022-36526
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

CVE-2022-36617
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.

CVE-2022-46484
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.

CVE-2022-37201
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-25258
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVE-2022-0617
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-476 2 PoCs

A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

CVE-2022-2245
Counter Box – WordPress plugin for countdown, timer, counter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

CVE-2022-24264
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
23.7%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

CVE-2022-32567
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.

CVE-2022-39803
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1800
Export any WordPress data to XML/CSV Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

CVE-2022-1354
libtiff General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-125 1 PoC

A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.

CVE-2022-3654
Chrome General
N/A
UNKNOWN
EPSS
3.7%
2022 1 PoC

Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-1625
New User Approve Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.

CVE-2022-28959
Software Genérico Web
N/A
UNKNOWN
EPSS
3.0%
2022 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.