7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25154
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows 7, 10, or 11 to exploit this vulnerability.)

CVE-2022-31499
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2022 3 PoCs

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

CVE-2022-2186
Simple Post Notes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-28381
Software Genérico General
N/A
UNKNOWN
EPSS
79.3%
2022 2 PoCs

Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.

CVE-2022-43712
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post unauthorized data to the server because of CVE-2022-22965.

CVE-2022-41176
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-1595
HC Custom WP-Admin URL Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.0%
2022 CWE-200 1 PoC

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

CVE-2022-0818
WooCommerce Affiliate Plugin – Coupon Affiliates Web Windows
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

CVE-2022-26149
Software Genérico General
N/A
UNKNOWN
EPSS
10.5%
2022 1 PoC

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

CVE-2022-1990
Nested Pages Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVE-2022-29349
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2022 0 PoCs

kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.

CVE-2022-22957
VMware Workspace ONE Access, Identity Manager and vRealize Automation. General
N/A
UNKNOWN
EPSS
43.2%
2022 2 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

CVE-2022-24347
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

CVE-2022-32532
Apache Shiro DevOps Web
N/A
UNKNOWN
EPSS
80.9%
2022 CWE-863 3 PoCs

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVE-2022-30276
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

CVE-2022-30858
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0

CVE-2022-32242
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-30242
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration chan

CVE-2022-43363
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relationship between the Pastebin information and a possible XSS finding.