7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28997
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

CVE-2022-29359
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2022 3 PoCs

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

CVE-2022-36622
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.

CVE-2022-27275
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.

CVE-2022-0701
Seo 301 Meta Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-28998
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.

CVE-2022-30040
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.

CVE-2022-38152
Software Genérico General
N/A
UNKNOWN
EPSS
2.7%
2022 2 PoCs

An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created through TLS session resumption and reuses the initial struct WOLFSSL. If the server reuses the previous session structure (struct WOLFSSL) by calling wolfSSL_clear(WOLFSSL* ssl) on it, the next received Client Hello (that resumes the previous session) crashes the server. Note that this bug is only triggered when resuming sessions using TLS session resumption.

CVE-2022-40621
WN531G3 Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-294 1 PoC

Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

CVE-2022-29156
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.

CVE-2022-23078
habitica General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-601 1 PoC

In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.

CVE-2022-0919
Salon booking system Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-862 1 PoC

The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.

CVE-2022-37175
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.

CVE-2022-23823
AMD Processors General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

CVE-2022-28530
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.

CVE-2022-1394
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-0703
GDMylist Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-36553
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 1 PoC

Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

CVE-2022-35150
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.

CVE-2022-32981
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.