7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-33119
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2022 0 PoCs

NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.

CVE-2022-1687
Logo Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection

CVE-2022-26105
SAP NetWeaver Enterprise Portal General
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-23944
Apache ShenYu (incubating) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2022 CWE-862 0 PoCs

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

CVE-2022-1573
HTML2WP Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them

CVE-2022-36117
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is configured to be accessible by a machine or the runtime resource security group, using further reverse engineering, an attacker can spoof a known machine and request known encrypted credentials to decrypt later.

CVE-2022-1572
HTML2WP Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

CVE-2022-33108
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.

CVE-2022-47696
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.

CVE-2022-26237
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

CVE-2022-1688
Note Press Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

CVE-2022-30778
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-25943
WPS Office for Windows Windows
N/A
UNKNOWN
EPSS
9.9%
2022 CWE-276 1 PoC

The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.

CVE-2022-22978
Spring Security DevOps Web
N/A
UNKNOWN
EPSS
90.2%
2022 CWE-863 8 PoCs

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVE-2022-20223
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 3 PoCs

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-223578534

CVE-2022-31886
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2022 2 PoCs

Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.

CVE-2022-1280
kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.

CVE-2022-45553
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.7%
2022 1 PoC

An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.

CVE-2022-2221
Remote Desktop Manager General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-200 1 PoC

Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8.

CVE-2022-2377
Directorist – WordPress Business Directory Plugin with Classified Ads Listings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog