7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1830
Amazon Einzeltitellinks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-31299
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.0%
2022 1 PoC

Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.

CVE-2022-26271
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.7%
2022 0 PoCs

74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

CVE-2022-20007
Android DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211481342

CVE-2022-0702
Petfinder Listings Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1646
Simple Real Estate Pack Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVE-2022-34619
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.

CVE-2022-31661
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-3168
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-27451
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

CVE-2022-27669
SAP NetWeaver Application Server for Java General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-862 1 PoC

An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.

CVE-2022-1539
Exports and Reports Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-1236 1 PoC

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

CVE-2022-0271
LearnPress – WordPress LMS Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 CWE-79 1 PoC

The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting

CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-34267
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.8%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.

CVE-2022-25106
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2022-32277
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about the Squiz Matrix CMS product.

CVE-2022-22970
Spring Framework Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-770 3 PoCs

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVE-2022-32192
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.