7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30513
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 2 PoCs

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

CVE-2022-0876
Social comments by WpDevArt Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-31269
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.0%
2022 4 PoCs

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

CVE-2022-30790
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

CVE-2022-22588
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.

CVE-2022-37892
Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; Web
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3

CVE-2022-1412
Log WP_Mail Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive information like generated passwords.

CVE-2022-1532
Themify – WooCommerce Product Filter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0725
keepass General
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-200 1 PoC

A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

CVE-2022-1275
BannerMan Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite)

CVE-2022-28350
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 2 PoCs

Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.

CVE-2022-34495
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

CVE-2022-1651
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-401 1 PoC

A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the ACRN Device Model emulates virtual NICs in VM. This flaw allows a local privileged attacker to leak unauthorized kernel information, causing a denial of service.

CVE-2022-0411
Asgaros Forum Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

CVE-2022-31493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.

CVE-2022-41401
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2022 1 PoC

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

CVE-2022-41175
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1589
Change wp-admin login Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

CVE-2022-27654
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-24574
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().