7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25262
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

CVE-2022-33705
Calendar General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-285 1 PoC

Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.

CVE-2022-25045
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

CVE-2022-41197
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-1709
Throws SPAM Away Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack

CVE-2022-20141
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel

CVE-2022-2340
W-DALIL Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 2 PoCs

The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-32007
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.

CVE-2022-29933
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2022 2 PoCs

Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).

CVE-2022-25521
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

NUUO v03.11.00 was discovered to contain access control issue.

CVE-2022-32395
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4

CVE-2022-0161
ARI Fancy Lightbox – WordPress Popup Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-28772
SAP NetWeaver (Internet Communication Manager) General
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-121 1 PoC

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

CVE-2022-38295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
43.0%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

CVE-2022-0431
Insights from Google PageSpeed Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-35899
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 4 PoCs

There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.

CVE-2022-1008
One Click Demo Import Web Windows
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-434 1 PoC

The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed

CVE-2022-29326
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

CVE-2022-36736
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed by the vendor

CVE-2022-25225
Network Olympus Web Database
N/A
UNKNOWN
EPSS
4.4%
2022 1 PoC

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.