7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1716
Keep My Notes General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

CVE-2022-34008
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.

CVE-2022-0817
BadgeOS Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.7%
2022 CWE-89 1 PoC

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-46485
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2022 2 PoCs

Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".

CVE-2022-24334
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

CVE-2022-2354
WP-DBManager Web Windows
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.

CVE-2022-27950
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.

CVE-2022-25797
Autodesk Trueview General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond the allocated buffer while parsing PDF files. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception.

CVE-2022-29824
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

CVE-2022-23713
kibana Web
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-79 1 PoC

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVE-2022-34578
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

CVE-2022-31403
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2022 1 PoC

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

CVE-2022-33980
Apache Commons Configuration Web
N/A
UNKNOWN
EPSS
86.7%
2022 7 PoCs

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (java

CVE-2022-29586
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB port, press F12, and then escape from the kiosk mode.

CVE-2022-41185
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-32159
infogami Web
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVE-2022-27531
Autodesk 3ds Max General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-29315
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.

CVE-2022-35589
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parameter.

CVE-2022-29598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .