7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2395
weForms – Easy Drag & Drop Contact Form Builder For WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-38817
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2022 0 PoCs

Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

CVE-2022-1164
WYZI Business Finder Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature

CVE-2022-29337
Software Genérico Web
N/A
UNKNOWN
EPSS
30.4%
2022 1 PoC

C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

CVE-2022-1298
Tabs Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-30037
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.

CVE-2022-23943
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
60.6%
2022 CWE-787 1 PoC

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

CVE-2022-36621
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.

CVE-2022-37134
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

CVE-2022-3239
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVE-2022-2414
Dogtag PKI Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2022 CWE-611 6 PoCs

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVE-2022-25242
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).

CVE-2022-28478
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

CVE-2022-35619
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2022 1 PoC

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.

CVE-2022-0788
WP Fundraising Donation and Crowdfunding Platform Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.1%
2022 CWE-89 1 PoC

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users

CVE-2022-29863
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

CVE-2022-38329
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, potentially causing the administrator to perform unintended actions on an affected system. The vulnerability could allow attackers to modify or delete specific content through crafted requests, potentially leading to data loss and system integrity issues.

CVE-2022-1321
miniOrange's Google Authenticator – WordPress Two Factor Authentication (2FA , Two Factor, OTP SMS and Email) | Passwordless login Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

CVE-2022-0659
Sync QCloud COS Web Cloud Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-28364
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.