7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-33147
AVideo Web Database
8.3
HIGH
EPSS
3.0%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the aVideoEncoder functionality which can be used to add new videos, allowing an attacker to inject SQL by manipulating the videoDownloadedLink or duration parameter.

CVE-2022-0218
WP HTML Mail Web Windows ⚡ nuclei
8.3
HIGH
EPSS
62.4%
2022 CWE-862 0 PoCs

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

CVE-2022-31176
grafana-image-renderer DevOps Web
8.3
HIGH
EPSS
0.6%
2022 CWE-200 1 PoC

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana). All Grafana installations should be upgraded to version 3.6.1 as soon as possible. As a workaround it is possible to [disable HTTP remote rendering](https://grafana.com/docs/grafana/latest/setup-graf

CVE-2022-1471
SnakeYAML General
8.3
HIGH
EPSS
93.8%
2022 CWE-20 2 PoCs

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVE-2022-4849
usememos/memos Web
8.3
HIGH
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1813
yogeshojha/rengine General
8.3
HIGH
EPSS
11.4%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.

CVE-2022-4865
usememos/memos Web
8.3
HIGH
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-3389
ikus060/rdiffweb General
8.2
HIGH
EPSS
0.6%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

CVE-2022-41966
xstream General
8.2
HIGH
EPSS
2.5%
2022 CWE-120 1 PoC

XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only

CVE-2022-2026
kromitgmbh/titra Web
8.2
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVE-2022-35886
iota All-In-One Security Kit Web
8.2
HIGH
EPSS
1.6%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` and `key` HTTP parameters, as used within the `/action/wirelessConnect` handler.

CVE-2022-48475
Control de Ciber General
8.2
HIGH
EPSS
0.7%
2022 CWE-400 1 PoC

Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could cause a Buffer Overflow when the adminitrator tries to accept or delete the print query created by the request.

CVE-2022-0894
pimcore/pimcore Web
8.2
HIGH
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-31363
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2022 1 PoC

Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered during mesh provisioning. Because there is no check for mismatched SegN and TotalLength in Transaction Start PDU.

CVE-2022-0860
cobbler/cobbler General
8.2
HIGH
EPSS
0.7%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

CVE-2022-4807
usememos/memos General
8.2
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-31364
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2022 1 PoC

Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered by sending a series of segmented packets with inconsistent SegN.

CVE-2022-0080
mruby/mruby General
8.2
HIGH
EPSS
0.2%
2022 CWE-122 1 PoC

mruby is vulnerable to Heap-based Buffer Overflow

CVE-2022-0951
star7th/showdoc Web
8.2
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-22999
My Cloud Web Cloud
8.2
HIGH
EPSS
0.6%
2022 CWE-79 1 PoC

Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may be possible to gain control over the authenticated session, steal data, modify settings, or redirect the user to malicious websites. The scope of impact can extend to other components.