7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37061
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2022 4 PoCs

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct

CVE-2022-36635
Software Genérico Database
N/A
UNKNOWN
EPSS
2.1%
2022 1 PoC

ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

CVE-2022-27349
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2022 2 PoCs

Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-35513
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2022 2 PoCs

The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.

CVE-2022-31798
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.6%
2022 3 PoCs

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-0590
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-1011
kernel General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-416 2 PoCs

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

CVE-2022-1577
Database Backup for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup schedule

CVE-2022-26499
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

CVE-2022-27256
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.

CVE-2022-2389
Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations

CVE-2022-28002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.

CVE-2022-2093
WP Duplicate Page Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-29968
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2022 1 PoC

An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.

CVE-2022-0349
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.5%
2022 CWE-89 1 PoC

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

CVE-2022-23349
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

CVE-2022-36534
Software Genérico Web
N/A
UNKNOWN
EPSS
74.9%
2022 1 PoC

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.

CVE-2022-36522
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

CVE-2022-22538
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below.

CVE-2022-1895
underConstruction Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack