7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2590
Linux kernel General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-362 1 PoC

A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.

CVE-2022-2050
WP-Paginate Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-41556
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2022 1 PoC

A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.

CVE-2022-1326
Form – Contact Form Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-28992
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

CVE-2022-27139
Software Genérico Web
N/A
UNKNOWN
EPSS
6.1%
2022 2 PoCs

An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated users. The uploading of SVG files to Ghost does not represent a remote code execution vulnerability. SVGs are not executable on the server, and may only execute javascript in a client's browser - this is expected and intentional functionality

CVE-2022-23222
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2022 4 PoCs

kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

CVE-2022-0150
WP Accessibility Helper (WAH) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-79 1 PoC

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

CVE-2022-23960
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

CVE-2022-1169
Careerfy Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

There is a XSS vulnerability in Careerfy.

CVE-2022-0347
LoginPress | Custom Login Page Customizer Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2022-1925
GStreamer General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-122 1 PoC

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

CVE-2022-26645
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2022 1 PoC

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

CVE-2022-1153
LayerSlider Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-79 1 PoC

The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in various place, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2022-31494
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.

CVE-2022-27192
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.

CVE-2022-35260
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-125 1 PoC

curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.

CVE-2022-45552
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.

CVE-2022-25082
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2022 0 PoCs

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVE-2022-22971
Spring Framework Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-770 2 PoCs

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.