7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24384
SmarterTrack Web ⚡ nuclei
8.8
HIGH
EPSS
48.0%
2022 CWE-79 0 PoCs

Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

CVE-2022-3537
Role Based Pricing for WooCommerce Web Windows
8.8
HIGH
EPSS
0.2%
2022 CWE-434 1 PoC

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP

CVE-2022-37209
Software Genérico Web Database
8.8
HIGH
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-24393
Fidelis Network Web
8.8
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response via an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVE-2022-37202
Software Genérico Web Database
8.8
HIGH
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

CVE-2022-39066
MF286R Database
8.8
HIGH
EPSS
51.1%
2022 1 PoC

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

CVE-2022-22111
DaybydayCRM General
8.8
HIGH
EPSS
0.3%
2022 CWE-862 1 PoC

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.

CVE-2022-31888
Software Genérico Web
8.8
HIGH
EPSS
2.4%
2022 1 PoC

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

CVE-2022-21613
Enterprise Data Quality Web Database
8.8
HIGH
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Data Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unautho

CVE-2022-36804
🔥 KEV Bitbucket Server Web ⚡ nuclei
8.8
HIGH
EPSS
94.4%
2022 26 PoCs

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CVE-2022-50694
Impact/Pulse/First Web Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unauthorized database information.

CVE-2022-26485
🔥 KEV Firefox General
8.8
HIGH
EPSS
7.2%
2022 1 PoC

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CVE-2022-45313
Software Genérico Networking
8.8
HIGH
EPSS
12.9%
2022 1 PoC

Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.

CVE-2022-28281
Thunderbird General
8.8
HIGH
EPSS
14.6%
2022 1 PoC

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVE-2022-23063
Shopizer General
8.8
HIGH
EPSS
0.3%
2022 CWE-613 1 PoC

In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

CVE-2022-42979
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link.

CVE-2022-22755
Firefox Web
8.8
HIGH
EPSS
0.8%
2022 2 PoCs

By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

CVE-2022-37719
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.

CVE-2022-0690
microweber/microweber Web
8.8
HIGH
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-23919
LinkHub Mesh Wifi General
8.8
HIGH
EPSS
0.5%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability leverages the name field within the protobuf message to cause a buffer overflow.