7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27352
Software Genérico Web
N/A
UNKNOWN
EPSS
2.5%
2022 1 PoC

Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-34966
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.

CVE-2022-24308
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process.

CVE-2022-36539
Software Genérico General
N/A
UNKNOWN
EPSS
6.5%
2022 1 PoC

WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.

CVE-2022-22539
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below.

CVE-2022-31206
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native machine code for execution by the PLC's runtime). The resulting machine code is executed by a runtime, typically controlled by a real-time operating system. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, allowing an attacker to manipulate transmitted object code to the PLC and ex

CVE-2022-23046
PhpIPAM Web Database
N/A
UNKNOWN
EPSS
49.0%
2022 5 PoCs

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

CVE-2022-41525
Software Genérico General
N/A
UNKNOWN
EPSS
14.5%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.

CVE-2022-1889
Newsletter – Send awesome emails from WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

CVE-2022-44276
Software Genérico General
N/A
UNKNOWN
EPSS
26.6%
2022 1 PoC

In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

CVE-2022-1273
Import WP – Import and Export WordPress data to XML or CSV files Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-434 1 PoC

The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE

CVE-2022-29005
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2022 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVE-2022-30518
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.

CVE-2022-2675
Go 1 General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-285 1 PoC

Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.

CVE-2022-40778
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to execute arbitrary JavaScript or HTML because of the blocked page response.

CVE-2022-1010
Login using WordPress Users ( WP as SAML IDP ) Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-2735
ClusterLabs/pcs General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-276 1 PoC

A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.

CVE-2022-25330
Trend Micro ServerProtect for Storage General
N/A
UNKNOWN
EPSS
4.9%
2022 1 PoC

Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.

CVE-2022-1684
CUBE SLIDER Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin