7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3154
Woo Billingo Plus Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license

CVE-2022-28109
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web server. The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine.

CVE-2022-28987
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.2%
2022 0 PoCs

Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.

CVE-2022-2271
WP Database Backup Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-25245
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2022 1 PoC

Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

CVE-2022-2535
SearchWP Live Ajax Search Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
18.4%
2022 CWE-639 1 PoC

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

CVE-2022-1255
Import and export users and customers Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

CVE-2022-23714
Endpoint Security Windows
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-264 1 PoC

A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

CVE-2022-0188
CMP Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 1 PoC

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

CVE-2022-20344
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-232541124

CVE-2022-1562
Enable SVG Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVE-2022-0493
String locator Web Windows
N/A
UNKNOWN
EPSS
1.0%
2022 CWE-22 1 PoC

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

CVE-2022-2194
Accept Stripe Payments Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0898
IgniteUp – Coming Soon and Maintenance Mode Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues

CVE-2022-22540
SAP NetWeaver AS ABAP (Workplace Server) General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-89 1 PoC

SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.

CVE-2022-28915
Software Genérico General
N/A
UNKNOWN
EPSS
33.4%
2022 1 PoC

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

CVE-2022-41761
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.

CVE-2022-2558
Simple Job Board Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-200 1 PoC

The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certain configurations.

CVE-2022-27447
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.

CVE-2022-20144
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-250637906