7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28000
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.

CVE-2022-0850
kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-200 1 PoC

A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.

CVE-2022-0747
Infographic Maker – iList Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.5%
2022 CWE-89 1 PoC

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-26562
Software Genérico General
N/A
UNKNOWN
EPSS
2.7%
2022 1 PoC

An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).

CVE-2022-29622
Software Genérico Web
N/A
UNKNOWN
EPSS
24.5%
2022 4 PoCs

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

CVE-2022-1016
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-824 1 PoC

A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.

CVE-2022-27535
Kaspersky VPN Secure Connection for Windows Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.

CVE-2022-31266
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.

CVE-2022-22734
Simple Quotation Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could make a logged in admin create or edit arbitrary quote, and put Cross-Site Scripting payloads in them

CVE-2022-25375
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

CVE-2022-25264
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

CVE-2022-48333
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow.

CVE-2022-32296
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

CVE-2022-40090
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.

CVE-2022-30903
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.

CVE-2022-30334
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixed by Brave, the Brave documentation still advises "Note that Private Windows with Tor Connectivity in Brave are just regular private windows that use Tor as a proxy. Brave does NOT implement most of the privacy protections from Tor Browser."

CVE-2022-29469
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-0778
OpenSSL General
N/A
UNKNOWN
EPSS
7.5%
2022 15 PoCs

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate ma

CVE-2022-30551
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.

CVE-2022-29328
Software Genérico General
N/A
UNKNOWN
EPSS
2.6%
2022 1 PoC

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.