7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28993
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.

CVE-2022-20126
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203431023

CVE-2022-24955
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

CVE-2022-26148
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 0 PoCs

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVE-2022-27406
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

CVE-2022-2384
Digital Publications by Supsystic Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-25813
Apache OFBiz Web
N/A
UNKNOWN
EPSS
60.3%
2022 CWE-1336 1 PoC

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

CVE-2022-1583
External Links in New Window / New Tab Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-1022 1 PoC

The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.

CVE-2022-35620
Software Genérico General
N/A
UNKNOWN
EPSS
25.2%
2022 1 PoC

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

CVE-2022-0313
Float menu – awesome floating side menu Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2022-3643
Linux Networking
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest of the Linux network stack that packet protocol headers are all contained within the linear section of the SKB and some NICs behave badly if this is not the case. This has been reported to occur with Cisco (enic) and Broadcom NetXtrem II BCM5780 (bnx2x) though it may be an issue with other NICs/drivers as well. In case the frontend is se

CVE-2022-23181
Apache Tomcat Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-367 3 PoCs

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVE-2022-48675
Linux General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix a nested dead lock as part of ODP flow Fix a nested dead lock as part of ODP flow by using mmput_async(). From the below call trace [1] can see that calling mmput() once we have the umem_odp->umem_mutex locked as required by ib_umem_odp_map_dma_and_lock() might trigger in the same task the exit_mmap()->__mmu_notifier_release()->mlx5_ib_invalidate_range() which may dead lock when trying to lock the same mutex. Moving to use mmput_async() will solve the problem as the above exit_mmap() flow will be called in oth

CVE-2022-24956
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.

CVE-2022-23348
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

CVE-2022-35193
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

CVE-2022-28932
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

CVE-2022-1541
Video Slider – Slider Carousel Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-39838
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

CVE-2022-33916
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.