7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-31664
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-25488
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
59.8%
2022 0 PoCs

Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

CVE-2022-1608
OnePress Social Locker Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-31782
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

CVE-2022-34048
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 0 PoCs

Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.

CVE-2022-28479
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

CVE-2022-23077
habitica Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.

CVE-2022-32250
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2022 13 PoCs

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

CVE-2022-37891
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; General
N/A
UNKNOWN
EPSS
3.0%
2022 1 PoC

Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.

CVE-2022-22850
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types.

CVE-2022-31660
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-41178
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-40715
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

CVE-2022-47069
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp. NOTE: the Supplier has found that this is not a buffer overflow; at most an out-of-bounds read can occur.

CVE-2022-32399
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4

CVE-2022-30314
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate firmware. The Honeywell Experion PKS Safety Manager utilizes the DCOM-232/485 serial interface for firmware management purposes. When booting, the Safety Manager exposes the Enea POLO bootloader via this interface. Access to the boot configuration is controlled by means of credentials hardcoded in the Safety Manager firm

CVE-2022-4953
Elementor Website Builder Web Windows
N/A
UNKNOWN
EPSS
11.5%
2022 2 PoCs

The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.

CVE-2022-36634
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.

CVE-2022-1679
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 2 PoCs

A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVE-2022-2887
WP Server Health Stats Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.