7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1601
User Access Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.

CVE-2022-2241
Featured Image from URL (FIFU) Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of validation, sanitisation and escaping in some of them, it could also lead to Stored XSS issues

CVE-2022-39816
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.

CVE-2022-39820
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all the PPS Network elements.

CVE-2022-1729
linux kernel General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-366 1 PoC

A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.

CVE-2022-2187
Contact Form 7 Captcha Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2022 CWE-79 1 PoC

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2022-39806
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Drawing (.slddrw, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-31845
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
53.1%
2022 0 PoCs

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVE-2022-28924
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.

CVE-2022-33995
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.

CVE-2022-36267
Software Genérico Web
N/A
UNKNOWN
EPSS
70.2%
2022 2 PoCs

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

CVE-2022-46408
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need admin/elevated access to exploit the vulnerability.

CVE-2022-24129
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
22.8%
2022 0 PoCs

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

CVE-2022-2011
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-26479
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

CVE-2022-35051
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b55af.

CVE-2022-47085
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.

CVE-2022-34093
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.5%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.

CVE-2022-22931
Apache James Web
N/A
UNKNOWN
EPSS
2.8%
2022 CWE-22 1 PoC

Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).

CVE-2022-0306
Chrome General
N/A
UNKNOWN
EPSS
6.5%
2022 1 PoC

Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.