7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27672
1st Gen AMD EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.

CVE-2022-2305
Popups – WordPress Popup Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WordPress Popup WordPress plugin through 1.9.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-22727
EcoStruxure Power Monitoring Expert (Versions 2020 and prior) General
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-20 1 PoC

A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

CVE-2022-0360
Easy Drag And drop All Import : WP Ultimate CSV Importer Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

CVE-2022-0255
Database Backup for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue

CVE-2022-30073
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.6%
2022 0 PoCs

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.

CVE-2022-2938
kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.

CVE-2022-25256
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL.

CVE-2022-28506
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.

CVE-2022-29014
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2022 2 PoCs

A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

CVE-2022-1756
Newsletter – Send awesome emails from WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2022 CWE-79 1 PoC

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

CVE-2022-1170
Noo JobMonster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-79 1 PoC

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-24130
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.

CVE-2022-31383
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

CVE-2022-32511
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2022 1 PoC

jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

CVE-2022-32559
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2022 2 PoCs

An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.

CVE-2022-25173
Jenkins Pipeline: Groovy Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-0434
Page View Count Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2022 CWE-89 1 PoC

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

CVE-2022-23305
Apache Log4j 1.x Web Database
N/A
UNKNOWN
EPSS
9.5%
2022 CWE-89 3 PoCs

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with pr