7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-29321
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2022 1 PoC

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

CVE-2022-34140
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.

CVE-2022-0388
Interactive Medical Drawing of Human Body Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0142
Visual Form Builder Web Windows
N/A
UNKNOWN
EPSS
4.7%
2022 CWE-1236 1 PoC

The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVE-2022-2565
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP Web Windows
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-79 1 PoC

The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins

CVE-2022-0376
User Meta – User Profile Builder and User management plugin Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-28962
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.

CVE-2022-41195
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Format (.iff, 2d.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-37191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.5%
2022 0 PoCs

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

CVE-2022-28077
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

CVE-2022-30318
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate configuration, denial of service. The Honeywell ControlEdge PLC and RTU product line exposes an SSH service on port 22/TCP. Login as root to this service is permitted and credentials for the root user are hardcoded without automatically changing them upon first commissioning. The credentials for the SSH service are hardcoded in the

CVE-2022-24288
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2022 CWE-78 0 PoCs

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

CVE-2022-37887
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; Web
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.

CVE-2022-30425
Software Genérico General
N/A
UNKNOWN
EPSS
18.9%
2022 1 PoC

Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This vulnerability is exploited via a crafted POST request.

CVE-2022-35910
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

CVE-2022-32442
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the parameter passed in is http://127.0.0.1/? "Onmouseover=%27tzgl (96502)%27bad=", it can cause html injection.

CVE-2022-0447
Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting

CVE-2022-0643
Bank Mellat Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-0739
BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin Web Database Windows
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 10 PoCs

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

CVE-2022-27532
Autodesk 3ds Max General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.