7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-20617
Jenkins Docker Commons Plugin DevOps
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.

CVE-2022-38789
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.

CVE-2022-22956
VMware Workspace ONE Access General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.9%
2022 2 PoCs

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

CVE-2022-0626
Advanced Admin Search Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting them back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-29735
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.

CVE-2022-24348
Software Genérico DevOps
N/A
UNKNOWN
EPSS
3.9%
2022 1 PoC

Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.

CVE-2022-39802
SAP Manufacturing Execution General
N/A
UNKNOWN
EPSS
3.7%
2022 CWE-22 3 PoCs

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

CVE-2022-24655
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.

CVE-2022-1528
VikBooking Hotel Booking Engine & PMS Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting

CVE-2022-32245
SAP BusinessObjects Business Intelligence Platform (Open Document) General
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-319 1 PoC

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.

CVE-2022-2035
Rustici Software SCORM Engine Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.

CVE-2022-29900
AMD Processors General
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVE-2022-28507
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Dragon Path Technologies Bharti Airtel Routers Hardware BDT-121 version 1.0 is vulnerable to Cross Site Scripting (XSS) via Dragon path router admin page.

CVE-2022-2362
Download Manager Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.

CVE-2022-29965
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corre

CVE-2022-1047
themify-ptb-search Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.

CVE-2022-40317
Software Genérico Web
N/A
UNKNOWN
EPSS
2.8%
2022 1 PoC

OpenKM 6.3.11 allows stored XSS related to the javascript&colon; substring in an A element.

CVE-2022-22833
Software Genérico General
N/A
UNKNOWN
EPSS
24.7%
2022 3 PoCs

An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.

CVE-2022-36115
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the CreateProcessAutosave() method to inject their own functionality into a development process. If (upon a warning) a user decides to recover unsaved work by using the last saved version, the malicious code could enter the workflow. Should the process action stages not be fully review

CVE-2022-28385
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2022 6 PoCs

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can manipulate the content of the emulated CD-ROM drive (containing the Windows and macOS client software). The content of this emulated CD-ROM drive is stored as an ISO-9660 image in the hidden sectors of the USB drive, that can only be accessed using special IOCTL commands, or when installing the drive in an external disk enclosure. By manipulating this ISO-9660 image or replacing it with another one, an attacker is able to store malicious software on the emulated CD-ROM drive.