7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0384
Video Conferencing with Zoom Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-200 1 PoC

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

CVE-2022-35122
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2022 1 PoC

An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords.

CVE-2022-0658
CommonsBooking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
47.3%
2022 CWE-89 1 PoC

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

CVE-2022-2763
WP Socializer – Simple & Easy Social Media Share Icons Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1265
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-28896
Software Genérico General
N/A
UNKNOWN
EPSS
33.4%
2022 1 PoC

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-1964
Easy SVG Support Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVE-2022-29862
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

CVE-2022-26188
Software Genérico General
N/A
UNKNOWN
EPSS
19.4%
2022 1 PoC

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.

CVE-2022-22533
SAP NetWeaver Application Server Java Web
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-416 1 PoC

Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in system shutdown rendering the system unavailable.

CVE-2022-25810
Transposh WordPress Translation Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-862 1 PoC

The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileged user. Basically all Utilities functionalities are vulnerable this way, which involves resetting configurations and backup/restore operations.

CVE-2022-39849
Samsung Mobile Devices Networking
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

CVE-2022-28328
SCALANCE W1788-1 M12 General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed Multicast LLC frames. This could allow an attacker to trigger a denial of service condition.

CVE-2022-0853
jboss-client General
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

CVE-2022-22814
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.

CVE-2022-4466
WordPress Infinite Scroll Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-26263
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2022 0 PoCs

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

CVE-2022-35590
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameter

CVE-2022-3209
soledad Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-34265
Software Genérico Database
N/A
UNKNOWN
EPSS
92.8%
2022 5 PoCs

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.