3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-41260
SAP Financial Consolidation General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-34474
Firefox General
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.

CVE-2022-0637
mozilla/pollbot General
6.1
MEDIUM
EPSS
0.2%
2022 2 PoCs

open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6

CVE-2022-22268
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.

CVE-2022-41275
Solution Manager (Enterprise Search) General
6.1
MEDIUM
EPSS
0.9%
2022 CWE-601 1 PoC

In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality and integrity.

CVE-2022-3362
ikus060/rdiffweb General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

CVE-2022-1619
vim/vim General
6.1
MEDIUM
EPSS
2.6%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution

CVE-2022-29912
Thunderbird General
6.1
MEDIUM
EPSS
0.5%
2022 1 PoC

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVE-2022-0198
stanfordnlp/corenlp General
6.1
MEDIUM
EPSS
0.2%
2022 CWE-611 1 PoC

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2022-36928
Zoom for Android General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-35 1 PoC

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.

CVE-2022-36182
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2022 2 PoCs

Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.

CVE-2022-36007
venice General
6.1
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue exists within the functions `load-file` and `load-resource`. These functions can be limited to load files from a list of load paths. Assuming Venice has been configured with the load paths: `[ "/Users/foo/resources" ]` When passing **relative** paths to these two vulnerable functions everything is fine: `(load-resource "test.png")` => loads the file "/Users/foo/resources/test.png" `(load-resource "../resources-alt/test.png")` => rejected, outside the load path When passing *

CVE-2022-41207
SAP Biller Direct General
6.1
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or modification of the victim's information.

CVE-2022-40956
Firefox ESR General
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVE-2022-4018
ikus060/rdiffweb General
6.1
MEDIUM
EPSS
0.4%
2022 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

CVE-2022-25479
Software Genérico General
6.1
MEDIUM
EPSS
2.8%
2022 2 PoCs

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.

CVE-2022-22555
PowerStore General
6.0
MEDIUM
EPSS
0.6%
2022 CWE-78 2 PoCs

Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.

CVE-2022-34449
PowerPath Management Appliance General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-798 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application.