7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-23987
WS Form LITE – Drag & Drop Contact Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-31595
SAP Financial Consolidation General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-862 1 PoC

SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

CVE-2022-20615
Jenkins Matrix Project Plugin DevOps Web
N/A
UNKNOWN
EPSS
2.9%
2022 1 PoC

Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

CVE-2022-23772
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

CVE-2022-27992
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.

CVE-2022-23909
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.

CVE-2022-48806
Linux Windows
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: eeprom: ee1004: limit i2c reads to I2C_SMBUS_BLOCK_MAX Commit effa453168a7 ("i2c: i801: Don't silently correct invalid transfer size") revealed that ee1004_eeprom_read() did not properly limit how many bytes to read at once. In particular, i2c_smbus_read_i2c_block_data_or_emulated() takes the length to read as an u8. If count == 256 after taking into account the offset and page boundary, the cast to u8 overflows. And this is common when user space tries to read the entire EEPROM at once. To fix it, limit each read to I2C

CVE-2022-22719
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
29.9%
2022 CWE-665 1 PoC

A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVE-2022-1335
Slideshow CK Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

CVE-2022-0389
WP Time Slots Booking Form Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-1847
Rotating Posts Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-0864
UpdraftPlus WordPress Backup Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2022 CWE-79 2 PoCs

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-0863
WP SVG Icons Web Windows
N/A
UNKNOWN
EPSS
13.3%
2022 CWE-434 1 PoC

The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.

CVE-2022-2299
Allow svg files Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVE-2022-27095
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-23051
PeTeReport Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.

CVE-2022-4174
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-32239
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 2 PoCs

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-35203
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2022 2 PoCs

An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

CVE-2022-26643
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.