7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0411
Asgaros Forum Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

CVE-2022-31493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.

CVE-2022-41401
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2022 1 PoC

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

CVE-2022-41175
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1589
Change wp-admin login Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

CVE-2022-27654
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-24574
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().

CVE-2022-31793
Software Genérico Web
N/A
UNKNOWN
EPSS
93.8%
2022 3 PoCs

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

CVE-2022-1906
Copyright Proof Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting when a specific setting is enabled.

CVE-2022-1049
clusterlabs/pcs General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-287 2 PoCs

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.

CVE-2022-29732
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-0422
White Label CMS Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2022 CWE-79 1 PoC

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

CVE-2022-41171
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-49046
Linux General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: i2c: dev: check return value when calling dev_set_name() If dev_set_name() fails, the dev_name() is null, check the return value of dev_set_name() to avoid the null-ptr-deref.

CVE-2022-28080
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
42.0%
2022 3 PoCs

Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.

CVE-2022-28773
SAP NetWeaver (Internet Communication Manager) General
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-674 1 PoC

Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.

CVE-2022-32061
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

CVE-2022-32561
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.

CVE-2022-26109
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-23126
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.