7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28994
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.

CVE-2022-32247
SAP NetWeaver Enterprise Portal General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-26238
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

CVE-2022-24327
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

CVE-2022-0487
kernel General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-416 1 PoC

A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.

CVE-2022-29776
Software Genérico General
N/A
UNKNOWN
EPSS
16.2%
2022 1 PoC

Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.

CVE-2022-32249
SAP Business one General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-668 1 PoC

Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credentials)

CVE-2022-36525
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.

CVE-2022-29320
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-28795
Avira Password Manager – Browser Extensions Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari.

CVE-2022-1915
WP Zillow Review Slider Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)

CVE-2022-1731
Metasonic Doc WebClient Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.

CVE-2022-0165
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2022 CWE-601 3 PoCs

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

CVE-2022-0662
AdRotate – Ad manager & AdSense Ads Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-37771
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.

CVE-2022-2091
Cache Images Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.

CVE-2022-32114
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2022 2 PoCs

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be able to upload PDF files containing JavaScript, and that all files in a public assets folder are accessible to the outside world (unless the filename begins with a dot character). The administrator can choose to allow only image, video, and audio files (i.e., not PDF) if desired.

CVE-2022-0149
WooCommerce – Store Exporter Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.