3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-39887
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

CVE-2022-2252
microweber/microweber General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

CVE-2022-1350
GhostPCL General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.

CVE-2022-0904
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.

CVE-2022-1079
One Church Management System General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are multiple files and parameters which are prone to to cross site scripting. It is possible to launch the attack remotely.

CVE-2022-42067
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability

CVE-2022-0597
microweber/microweber General ⚡ nuclei
4.3
MEDIUM
EPSS
1.0%
2022 CWE-601 1 PoC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-39873
Samsung Internet General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.

CVE-2022-0405
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.

CVE-2022-37426
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

CVE-2022-36771
QRadar User Behavior Analytics General
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.

CVE-2022-1074
FLEX-1085 General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-74 1 PoC

A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of the dashboard leads to html injection.

CVE-2022-0746
dolibarr/dolibarr General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-0273
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control in Pypi calibreweb prior to 0.6.16.

CVE-2022-25783
GateManager General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-778 1 PoC

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-39891
Editor Lite General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

CVE-2022-4044
Mattermost General
4.3
MEDIUM
EPSS
0.5%
2022 CWE-770 1 PoC

A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.

CVE-2022-1004
OTRS General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.

CVE-2022-3826
ERP General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-266 1 PoC

A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file /depotHead/list of the component Retail Management. The manipulation of the argument search leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212793 was assigned to this vulnerability.

CVE-2022-1337
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.