7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30045
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.

CVE-2022-28348
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.

CVE-2022-31680
VMware vCenter Server General
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.

CVE-2022-29731
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.

CVE-2022-34102
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.

CVE-2022-1558
Curtain Web Windows
N/A
UNKNOWN
EPSS
2.4%
2022 CWE-79 2 PoCs

The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVE-2022-28893
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

CVE-2022-1472
Better Find and Replace Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

CVE-2022-47002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.0%
2022 0 PoCs

A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

CVE-2022-22702
PartKeepr General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.

CVE-2022-2392
Lana Downloads Manager Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-552 1 PoC

The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

CVE-2022-37400
Apache OpenOffice Web
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-330 1 PoC

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice

CVE-2022-27386
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.

CVE-2022-35226
SAP Data Services Management Console Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console.

CVE-2022-37128
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

CVE-2022-36636
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.

CVE-2022-33709
Galaxy Store General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

CVE-2022-32065
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.

CVE-2022-22832
Software Genérico General
N/A
UNKNOWN
EPSS
23.3%
2022 3 PoCs

An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.

CVE-2022-25227
Thinfinity VNC General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.