7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0337
Chrome Web Windows
N/A
UNKNOWN
EPSS
11.7%
2022 3 PoCs

Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. (Chrome security severity: High)

CVE-2022-32195
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2022 0 PoCs

Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

CVE-2022-41762
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.

CVE-2022-1418
Social Stickers Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-79 1 PoC

The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.

CVE-2022-35297
SAP Enable Now Web
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.

CVE-2022-31854
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 3 PoCs

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

CVE-2022-26588
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.

CVE-2022-33993
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.

CVE-2022-27293
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVE-2022-1465
WPC Smart Wishlist for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

CVE-2022-0837
Amelia Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.

CVE-2022-32310
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.

CVE-2022-26106
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-41190
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1582
External Links in New Window / New Tab Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.

CVE-2022-23119
Trend Micro Deep Security Agent for Linux Cloud
N/A
UNKNOWN
EPSS
1.2%
2022 2 PoCs

A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.

CVE-2022-26634
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-1281
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Database Windows
N/A
UNKNOWN
EPSS
6.0%
2022 CWE-89 1 PoC

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

CVE-2022-36669
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2022-23056
erpnext Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.