7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28349
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.

CVE-2022-32562
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.

CVE-2022-25064
Software Genérico General
N/A
UNKNOWN
EPSS
63.1%
2022 2 PoCs

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

CVE-2022-2071
Name Directory Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.

CVE-2022-34567
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

An issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escalate privileges via crafted plugins.

CVE-2022-26624
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.

CVE-2022-27272
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.

CVE-2022-1556
StaffList Web Database Windows
N/A
UNKNOWN
EPSS
8.8%
2022 CWE-89 2 PoCs

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

CVE-2022-30017
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.

CVE-2022-25261
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.

CVE-2022-24957
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object and use the XSS payload as the name. Any user that opens the object's version or history tab will be attacked.

CVE-2022-0214
Popup | Custom Popup Builder Web Windows
N/A
UNKNOWN
EPSS
2.0%
2022 1 PoC

The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

CVE-2022-26564
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2022 0 PoCs

HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.

CVE-2022-0918
389-ds-base Windows
N/A
UNKNOWN
EPSS
7.7%
2022 1 PoC

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

CVE-2022-1029
Limit Login Attempts Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

CVE-2022-25581
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

CVE-2022-32190
net/url Web
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.

CVE-2022-30514
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 2 PoCs

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.

CVE-2022-23302
Apache Log4j 1.x Web Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-502 2 PoCs

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upg

CVE-2022-1599
Admin Management Xtended Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.