7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-47695
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.

CVE-2022-36234
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.

CVE-2022-1724
Simple Membership Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2022 CWE-79 1 PoC

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

CVE-2022-0171
kernel Web
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-459 1 PoC

A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).

CVE-2022-32993
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

CVE-2022-1560
Amministrazione Aperta Web Windows
N/A
UNKNOWN
EPSS
22.4%
2022 CWE-22 1 PoC

The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link

CVE-2022-22835
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.

CVE-2022-22735
Simple Quotation Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacks

CVE-2022-1269
Fast Flow Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2022-24337
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

CVE-2022-0707
Easy Digital Downloads – Simple eCommerce for Selling Digital Files Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack

CVE-2022-1322
Coming Soon – Under Construction Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-29727
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2022 1 PoC

Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.

CVE-2022-28590
Software Genérico Web
N/A
UNKNOWN
EPSS
39.3%
2022 2 PoCs

A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.

CVE-2022-28397
Software Genérico Web
N/A
UNKNOWN
EPSS
4.0%
2022 2 PoCs

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional

CVE-2022-2448
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-37133
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.

CVE-2022-25229
Popcorn Time Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

CVE-2022-48545
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.

CVE-2022-30273
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers.