7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36203
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.

CVE-2022-1203
Content Mask Web Windows
N/A
UNKNOWN
EPSS
4.5%
2022 2 PoCs

The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options

CVE-2022-2369
YaySMTP – Simple WP SMTP Mail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-862 1 PoC

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

CVE-2022-24406
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.

CVE-2022-0516
kernel Cloud
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-200 1 PoC

A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.

CVE-2022-23055
frappe General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-862 1 PoC

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

CVE-2022-0314
Nimble Page Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-27984
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-26653
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).

CVE-2022-28346
Software Genérico Database
N/A
UNKNOWN
EPSS
2.0%
2022 7 PoCs

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVE-2022-25174
Jenkins Pipeline: Shared Groovy Libraries Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-1894
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed

CVE-2022-26498
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

CVE-2022-1791
One Click Plugin Updater Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.

CVE-2022-35019
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVE-2022-20413
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634

CVE-2022-30852
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).

CVE-2022-0760
Simple Link Directory Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.3%
2022 CWE-89 1 PoC

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-0363
myCred Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.

CVE-2022-41722
path/filepath Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".