7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2268
Import any XML or CSV File to WordPress Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-434 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

CVE-2022-27270
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.

CVE-2022-27248
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint. An attack uses the path field to CaddemServiceJS/CaddemService.svc/rest/DownloadDwg.

CVE-2022-0248
Contact Form Submissions Web Windows
N/A
UNKNOWN
EPSS
14.8%
2022 CWE-79 1 PoC

The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission

CVE-2022-1951
core plugin for kitestudio themes Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting.

CVE-2022-1610
Seamless Donations: A Platform for Global Fundraising and Rebuilding using Stripe and PayPal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-36116
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the setValidationInfo administrative function. Removing the validation applied to newly designed processes increases the chance of successfully hiding malicious code that could be executed in a production environment.

CVE-2022-29153
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.8%
2022 2 PoCs

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

CVE-2022-36945
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2022 5 PoCs

The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.

CVE-2022-2100
Page Generator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-29063
Apache OFBiz Web
N/A
UNKNOWN
EPSS
20.8%
2022 CWE-502 2 PoCs

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.

CVE-2022-4058
Photo Gallery by 10Web Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later on in another page, which could lead to Stored XSS issue when an attacker makes a logged in admin open a malicious URL or page under their control.

CVE-2022-25343
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial of Service. An unauthenticated attacker, who can send POST requests to the /download/set.cgi page by manipulating the failhtmfile variable, is able to cause interruption of the service provided by the Web Application.

CVE-2022-27135
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

CVE-2022-45703
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

CVE-2022-1671
Kernel General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-476 1 PoC

A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.

CVE-2022-35225
SAP NetWeaver Enterprise Portal Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.

CVE-2022-2423
DW Promobar Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0732
Copy9 Web
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-284 1 PoC

The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

CVE-2022-34046
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2022 2 PoCs

An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].