7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24247
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2022 2 PoCs

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write) resulting a remote code execution.

CVE-2022-25224
Proton Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Proton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the application opens the site in the current frame allowing an attacker to host JavaScript code in the malicious link in order to trigger an XSS attack. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

CVE-2022-26651
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.8-cert14.

CVE-2022-0412
TI WooCommerce Wishlist Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-89 2 PoCs

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

CVE-2022-30079
Software Genérico General
N/A
UNKNOWN
EPSS
11.0%
2022 2 PoCs

Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.

CVE-2022-27985
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-0700
Simple Tracking Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-38788
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

CVE-2022-2261
WPIDE – File Manager & Code Editor Web Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-22 1 PoC

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.

CVE-2022-23907
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

CVE-2022-27882
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.

CVE-2022-1697
Okta Active Directory Agent Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

CVE-2022-32240
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-3656
Chrome General
N/A
UNKNOWN
EPSS
2.6%
2022 1 PoC

Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2022-0737
Text Hover Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-27452
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.

CVE-2022-1885
Cimy Header Image Rotator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-24328
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.

CVE-2022-27387
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

CVE-2022-31658
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
3.8%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.