7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0403
Library File Manager Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-434 1 PoC

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

CVE-2022-35414
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.

CVE-2022-30015
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.

CVE-2022-29730
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.

CVE-2022-2356
Frontend File Manager & Sharing – User Private Files Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-434 1 PoC

The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

CVE-2022-23101
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.

CVE-2022-30326
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The network pre-shared key field on the web interface is vulnerable to XSS. An attacker can use a simple XSS payload to crash the basic.config page of the web interface.

CVE-2022-27269
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.

CVE-2022-41166
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-46786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).

CVE-2022-48656
Linux General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma-private: Fix refcount leak bug in of_xudma_dev_get() We should call of_node_put() for the reference returned by of_parse_phandle() in fail path or when it is not used anymore. Here we only need to move the of_node_put() before the check.

CVE-2022-1903
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.4%
2022 CWE-862 2 PoCs

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

CVE-2022-0995
kernel General
N/A
UNKNOWN
EPSS
17.0%
2022 CWE-787 8 PoCs

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

CVE-2022-2554
Enable Media Replace Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-22 1 PoC

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

CVE-2022-1323
Discy Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.

CVE-2022-1937
Awin Data Feed Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2022 CWE-79 1 PoC

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVE-2022-35224
SAP Enterprise Portal Web
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-79 1 PoC

SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim�s web browser session.

CVE-2022-26952
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.

CVE-2022-36752
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png file.

CVE-2022-34494
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.