7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37153
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2022 1 PoC

An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.

CVE-2022-25342
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for access to resources, it allows a potential attacker to view pages that are not allowed.

CVE-2022-46891
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r13p0 through r32p0, Bifrost r1p0 through r40p0, and Valhall r19p0 through r40p0.

CVE-2022-0441
MasterStudy LMS – WordPress LMS Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 CWE-269 5 PoCs

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

CVE-2022-29734
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVE-2022-24696
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a local attacker to elevate privileges. NOTE: this is unrelated to products from the glance.com and glance.net websites.

CVE-2022-0592
MapSVG Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 1 PoC

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVE-2022-34831
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an identifier for one or multiple dnsNames. These are validated properly in the ACME challenge. However, if the validation passes, a non-compliant client can include additional dnsNames the CSR sent to the finalize endpoint, resulting in EJBCA issuing a certificate including the identifiers that were not validated. This occu

CVE-2022-46784
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)

CVE-2022-0168
kernel Windows
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-476 1 PoC

A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.

CVE-2022-50934
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-0994
Hummingbird – Optimize Speed, Enable Cache, Minify CSS & Defer Critical JS Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-28770
SAPUI5 (vbm library) General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-0531
Migration, Backup, Staging – WPvivid Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting

CVE-2022-1953
Product Configurator for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
3.9%
2022 CWE-22 1 PoC

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

CVE-2022-30245
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration change, remediation requires

CVE-2022-0953
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

CVE-2022-25096
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.

CVE-2022-3125
Frontend File Manager Plugin Web Windows
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-434 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

CVE-2022-1946
Gallery – Image and Video Gallery with Thumbnails Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-79 1 PoC

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue