7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0783
Multiple Shipping Address Woocommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.5%
2022 CWE-89 1 PoC

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

CVE-2022-22701
PartKeepr General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

CVE-2022-1474
WP Event Manager – Easily Build your Calendar of Events! Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

CVE-2022-36532
Software Genérico Web
N/A
UNKNOWN
EPSS
24.8%
2022 2 PoCs

Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.

CVE-2022-23911
Testimonial WordPress Plugin – AP Custom Testimonial Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

CVE-2022-24345
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

CVE-2022-1663
Stop Spam Comments Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-200 1 PoC

The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.

CVE-2022-26497
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.

CVE-2022-26507
Software Genérico General
N/A
UNKNOWN
EPSS
6.7%
2022 2 PoCs

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-2316
Devolutions Server General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.

CVE-2022-39815
Software Genérico General
N/A
UNKNOWN
EPSS
13.5%
2022 1 PoC

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

CVE-2022-30262
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVE-2022-0216
QEMU General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.

CVE-2022-0914
Export All URLs Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVE-2022-0385
Crazy Bone Web Windows
N/A
UNKNOWN
EPSS
6.0%
2022 CWE-79 1 PoC

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

CVE-2022-31591
SAP BusinessObjects (BW Publisher Service) General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-428 1 PoC

SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service

CVE-2022-26239
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

CVE-2022-38637
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

CVE-2022-48336
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow.

CVE-2022-23079
motor-admin General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-116 1 PoC

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.