7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-23806
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVE-2022-36119
Software Genérico General
N/A
UNKNOWN
EPSS
6.9%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of insecure deserialization. Exploitation of this vulnerability allows for code to be executed in the context of the Blue Prism Server service.

CVE-2022-25389
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the file /audit/log/log_management.php.

CVE-2022-0345
Customize WordPress Emails and Alerts Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).

CVE-2022-30776
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
45.5%
2022 2 PoCs

atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.

CVE-2022-38322
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-27481
SCALANCE W1788-1 M12 General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-362 1 PoC

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle resources of ARP requests. This could allow an attacker to cause a race condition that leads to a crash of the entire device.

CVE-2022-31398
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

CVE-2022-1957
Comment License Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-27413
Software Genérico Web Database
N/A
UNKNOWN
EPSS
12.0%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.

CVE-2022-0920
Salon booking system Web Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-863 1 PoC

The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data

CVE-2022-0190
Ad Invalid Click Protector (AICP) Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-89 1 PoC

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.

CVE-2022-0321
WP Voting Contest Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting it back in the response via the wpvc_social_share_icons AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

CVE-2022-37057
Software Genérico General
N/A
UNKNOWN
EPSS
31.8%
2022 2 PoCs

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.

CVE-2022-40734
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2022 0 PoCs

UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.

CVE-2022-28508
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.

CVE-2022-30292
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2022 1 PoC

Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.

CVE-2022-1732
Rename wp-login.php Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-28363
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2022 2 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.