7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24263
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.9%
2022 3 PoCs

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

CVE-2022-34903
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVE-2022-36131
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Templates overview page.

CVE-2022-31492
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.

CVE-2022-28919
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.

CVE-2022-39028
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was remov

CVE-2022-2168
Download Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 CWE-79 1 PoC

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-30910
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the GO parameter at /goform/aspForm.

CVE-2022-27527
Navisworks General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFTron earlier than 9.0.7 version in Autodesk Navisworks 2022, and 2020.

CVE-2022-1113
Flower Delivery by Florist One Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups)

CVE-2022-2078
kernel General
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-121 2 PoCs

A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.

CVE-2022-1325
Clmg General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-400 2 PoCs

A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual buffer.

CVE-2022-2149
Very Simple Breadcrumb Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-25322
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2022 0 PoCs

ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

CVE-2022-2567
Form Builder CP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-33706
Samsung Gallery General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.

CVE-2022-29009
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 2 PoCs

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

CVE-2022-37401
Apache OpenOffice Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-331 1 PoC

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulnerable to a brute force attack if an attacker has access to the users stored config. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26307 - LibreOffice

CVE-2022-28864
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.

CVE-2022-37130
Software Genérico General
N/A
UNKNOWN
EPSS
30.3%
2022 1 PoC

In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability