7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-32089
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVE-2022-0246
iQ Block Country Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-73 1 PoC

The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the extraction process, existence of a file is checked. If the file exists, it is deleted without any security control by only considering the name of the extracted file. This behavior leads to "Zip Slip" vulnerability.

CVE-2022-2412
Better Tag Cloud Web Cloud Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-32022
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

CVE-2022-26482
Software Genérico General
N/A
UNKNOWN
EPSS
23.6%
2022 1 PoC

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.

CVE-2022-0969
Image optimization & Lazy Load by Optimole Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0267
AdRotate – Ad manager & AdSense Ads Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

CVE-2022-48612
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable places.

CVE-2022-48560
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVE-2022-24223
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
27.5%
2022 1 PoC

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

CVE-2022-2544
Ninja Job Board – Ultimate WordPress Job Board Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.5%
2022 CWE-425 2 PoCs

The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

CVE-2022-24975
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

CVE-2022-28387
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 6 PoCs

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1 and Fingerprint Secure Portable Hard Drive Part Number #53650.

CVE-2022-1425
WPQA Builder Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read messages for any other users via a Insecure Direct Object Reference (IDOR) vulnerability.

CVE-2022-31590
SAP PowerDesigner Proxy 16.7 General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-428 1 PoC

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.

CVE-2022-23100
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2022 1 PoC

OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

CVE-2022-45218
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulnerability is triggered via a crafted payload injected into an authentication error message.

CVE-2022-27294
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVE-2022-27286
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

CVE-2022-2629
Top Bar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in frontend pages, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)