7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4813
usememos/memos General
8.6
HIGH
EPSS
0.3%
2022 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-3805
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress Web Windows ⚡ nuclei
8.6
HIGH
EPSS
8.5%
2022 CWE-639 0 PoCs

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

CVE-2022-4686
usememos/memos General
8.6
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-50939
e107 CMS Web
8.6
HIGH
EPSS
0.7%
2022 CWE-22 1 PoC

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (image.php) where the upload_caption parameter is not properly sanitized. An attacker with administrative privileges can use directory traversal sequences (../../../) in the upload_caption field to overwrite critical system files outside the intended upload directory. This can lead to complete compromise of the web application by overwriting configu

CVE-2022-2713
cockpit-hq/cockpit General
8.6
HIGH
EPSS
1.1%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

CVE-2022-23425
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

CVE-2022-42844
iOS and iPadOS General
8.6
HIGH
EPSS
0.2%
2022 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox.

CVE-2022-4848
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-940 1 PoC

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4800
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-940 1 PoC

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4812
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-41412
Software Genérico General ⚡ nuclei
8.6
HIGH
EPSS
89.4%
2022 2 PoCs

An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.

CVE-2022-41985
uC-FTPs General
8.6
HIGH
EPSS
0.1%
2022 CWE-303 1 PoC

An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

CVE-2022-23923
jailed General
8.6
HIGH
EPSS
0.1%
2022 2 PoCs

All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.

CVE-2022-50922
Audio Conversion Wizard General
8.6
HIGH
EPSS
0.3%
2022 CWE-120 1 PoC

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.

CVE-2022-33719
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.2%
2022 CWE-20 1 PoC

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

CVE-2022-50907
e107 CMS Web
8.6
HIGH
EPSS
0.5%
2022 CWE-434 1 PoC

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.

CVE-2022-50909
Algo 8028 General
8.6
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.

CVE-2022-4841
usememos/memos Web
8.6
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4136
qmpaas/leadshop Web
8.6
HIGH
EPSS
0.4%
2022 CWE-749 1 PoC

Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method.

CVE-2022-50898
NanoCMS Web
8.6
HIGH
EPSS
0.4%
2022 CWE-434 1 PoC

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.