7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27095
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-23051
PeTeReport Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.

CVE-2022-4174
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-32239
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 2 PoCs

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-35203
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2022 2 PoCs

An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

CVE-2022-26643
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.

CVE-2022-1168
WP JobSearch Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2022 CWE-79 1 PoC

There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

CVE-2022-24260
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2022 0 PoCs

A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

CVE-2022-26307
LibreOffice General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-326 1 PoC

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3.

CVE-2022-29932
Software Genérico Web
N/A
UNKNOWN
EPSS
4.4%
2022 2 PoCs

The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

CVE-2022-31268
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2022 0 PoCs

A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).

CVE-2022-1551
SP Project & Document Manager Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.

CVE-2022-30513
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 2 PoCs

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

CVE-2022-0876
Social comments by WpDevArt Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-31269
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.0%
2022 4 PoCs

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

CVE-2022-30790
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

CVE-2022-22588
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.

CVE-2022-37892
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; Web
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3

CVE-2022-1412
Log WP_Mail Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive information like generated passwords.

CVE-2022-0725
keepass General
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-200 1 PoC

A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.