7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-29158
Apache OFBiz Web
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-1333 1 PoC

Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599

CVE-2022-2410
mTouch Quiz Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-34006
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITY\SYSTEM, aka NX-I674 (sub-issue 2). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.

CVE-2022-40140
Trend Micro Apex One General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVE-2022-29652
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.

CVE-2022-26646
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.

CVE-2022-0533
Ditty (formerly Ditty News Ticker) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2022 CWE-79 1 PoC

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-4115
Editorial Calendar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users.

CVE-2022-1570
Files Download Delay Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.

CVE-2022-24253
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

CVE-2022-2275
WP Edit Menu Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack

CVE-2022-27276
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.

CVE-2022-25486
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

CVE-2022-23102
SINEMA Remote Connect Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 CWE-601 2 PoCs

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.

CVE-2022-23849
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.

CVE-2022-40896
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

CVE-2022-39821
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.

CVE-2022-28961
Software Genérico Database
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.

CVE-2022-30552
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Das U-Boot 2022.01 has a Buffer Overflow.

CVE-2022-2382
Product Slider for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.