7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-26107
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-2072
Name Directory Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVE-2022-25485
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
37.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

CVE-2022-30874
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.

CVE-2022-29347
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

CVE-2022-0492
kernel General
N/A
UNKNOWN
EPSS
5.2%
2022 CWE-287 12 PoCs

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

CVE-2022-0429
WP Cerber Security, Anti-spam & Malware Scan Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

CVE-2022-28531
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.

CVE-2022-0661
Ad Injection Web Windows
N/A
UNKNOWN
EPSS
11.8%
2022 CWE-94 1 PoC

The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.

CVE-2022-49261
Linux General
N/A
UNKNOWN
EPSS
0.0%
2022 5 PoCs

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: add missing boundary check in vm_access A missing bounds check in vm_access() can lead to an out-of-bounds read or write in the adjacent memory area, since the len attribute is not validated before the memcpy later in the function, potentially hitting: [ 183.637831] BUG: unable to handle page fault for address: ffffc90000c86000 [ 183.637934] #PF: supervisor read access in kernel mode [ 183.637997] #PF: error_code(0x0000) - not-present page [ 183.638059] PGD 100000067 P4D 100000067 PUD 100258067 PMD 1063410

CVE-2022-46080
Software Genérico Web
N/A
UNKNOWN
EPSS
15.2%
2022 3 PoCs

Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

CVE-2022-32223
Node Windows
N/A
UNKNOWN
EPSS
8.1%
2022 CWE-427 1 PoC

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variet

CVE-2022-23865
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter.

CVE-2022-23047
Exponent CMS Web
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

CVE-2022-39814
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

CVE-2022-32402
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4

CVE-2022-22537
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below.

CVE-2022-28290
WordPress Country Selector Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2022 CWE-79 1 PoC

Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request

CVE-2022-47083
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.

CVE-2022-36524
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.