7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30335
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

CVE-2022-1603
Mail Subscribe List Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list

CVE-2022-2379
Easy Student Results Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
36.5%
2022 CWE-862 1 PoC

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

CVE-2022-34973
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.

CVE-2022-0322
kernel General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-681 2 PoCs

A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).

CVE-2022-32563
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials provided to the Admin REST API are ignored, resulting in privilege escalation for unauthenticated users. The Public REST API is not impacted by this issue. A workaround is to replace X.509 certificate based authentication with Username and Password authentication inside the bootstr

CVE-2022-27292
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

CVE-2022-37203
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-26147
Software Genérico General
N/A
UNKNOWN
EPSS
12.6%
2022 1 PoC

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVE-2022-0594
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
44.0%
2022 CWE-863 1 PoC

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

CVE-2022-41187
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-31887
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.

CVE-2022-0833
Church Admin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data

CVE-2022-0786
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.2%
2022 CWE-89 1 PoC

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

CVE-2022-42045
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 2 PoCs

Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28.

CVE-2022-35174
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.

CVE-2022-2958
BadgeOS Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

CVE-2022-34974
Software Genérico General
N/A
UNKNOWN
EPSS
22.3%
2022 1 PoC

D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.

CVE-2022-26265
Software Genérico Web
N/A
UNKNOWN
EPSS
71.5%
2022 3 PoCs

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

CVE-2022-37894
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vu