7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-34005
Software Genérico Database
N/A
UNKNOWN
EPSS
1.6%
2022 1 PoC

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue 1). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.

CVE-2022-1977
Import Export All WordPress Images, Users & Post Types Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-918 1 PoC

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

CVE-2022-28571
Software Genérico General
N/A
UNKNOWN
EPSS
17.4%
2022 2 PoCs

D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

CVE-2022-0176
PowerPack Lite for Beaver Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0186
Image Photo Gallery Final Tiles Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

CVE-2022-22544
SAP Solution Manager (Diagnostics Root Cause Analysis Tools) General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing segregation of duty for the SAP Solution Manager administrator. Impacts of unauthorized execution of commands can lead to sensitive information disclosure, loss of system integrity and denial of service.

CVE-2022-0892
Export All URLs Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-24576
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

GPAC 1.0.1 is affected by Use After Free through MP4Box.

CVE-2022-30329
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 2 PoCs

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands.

CVE-2022-0199
Coming soon and Maintenance mode Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

CVE-2022-31897
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2022 3 PoCs

SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.

CVE-2022-1202
WP-CRM – Customer Relations Management for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-1236 1 PoC

The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.

CVE-2022-46196
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-23043
Zenario CMS Web
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

CVE-2022-0290
Chrome General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVE-2022-36123
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.

CVE-2022-27348
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2022 2 PoCs

Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.

CVE-2022-27927
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2022 2 PoCs

A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.

CVE-2022-2532
Feed Them Social – for Twitter feed, Youtube and more Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-25222
Money Transfer Management System Web Database
N/A
UNKNOWN
EPSS
2.7%
2022 1 PoC

Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.