7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22853
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Name field.

CVE-2022-28944
Software Genérico Windows
N/A
UNKNOWN
EPSS
10.9%
2022 3 PoCs

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO S

CVE-2022-27385
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVE-2022-41167
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-30050
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.

CVE-2022-1943
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-787 1 PoC

A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially

CVE-2022-2556
Mailchimp for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-918 1 PoC

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

CVE-2022-1037
EXMAGE – WordPress Image Links Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-918 1 PoC

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVE-2022-26521
Software Genérico Web
N/A
UNKNOWN
EPSS
7.8%
2022 1 PoC

Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).

CVE-2022-2832
Blender General
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-395 2 PoCs

A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.

CVE-2022-2099
WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

CVE-2022-0595
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVE-2022-22909
Software Genérico General
N/A
UNKNOWN
EPSS
33.1%
2022 2 PoCs

HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.

CVE-2022-2278
Featured Image from URL (FIFU) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-33711
Samsung USB Driver Windows Installer for Mobile Phones Windows
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-354 1 PoC

Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction.

CVE-2022-4125
Popup Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well

CVE-2022-33116
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitrary files via a directory traversal.

CVE-2022-36637
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter at /brand.php.

CVE-2022-24333
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

CVE-2022-21824
Node General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-471 2 PoCs

Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.