3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0726
chocobozzz/peertube General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

CVE-2022-25782
GateManager General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-274 1 PoC

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-26950
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

CVE-2022-0731
dolibarr/dolibarr General
5.4
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-3774
Train Scheduler App General
5.4
MEDIUM
EPSS
0.5%
2022 CWE-99 2 PoCs

A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource identifiers. The attack may be launched remotely. The identifier of this vulnerability is VDB-212504.

CVE-2022-45096
PowerScale OneFS General
5.4
MEDIUM
EPSS
0.7%
2022 CWE-355 1 PoC

Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information.

CVE-2022-23068
ToolJet General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-74 1 PoC

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

CVE-2022-1036
microweber/microweber General
5.3
MEDIUM
EPSS
0.7%
2022 CWE-190 1 PoC

Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-26049
com.diffplug.gradle:goomph General
5.3
MEDIUM
EPSS
1.7%
2022 1 PoC

This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve remote code execution on a target system by exploiting this vulnerability. **Note:** This could have allowed a malicious zip file to extract itself into an arbitrary directory. The only file that Goomph extracts is the p2 bootstrapper and eclipse metadata files hosted at eclipse.org, which are not mali

CVE-2022-2400
dompdf/dompdf General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

CVE-2022-0170
chocobozzz/peertube General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

peertube is vulnerable to Improper Access Control

CVE-2022-0574
publify/publify General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

CVE-2022-42892
syngo Dynamics General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-23 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder accessible to the account assigned to the website’s application pool.

CVE-2022-23001
Sweet B Library General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-682 1 PoC

When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user level privileges and no other user's assistance can exploit this vulnerability with only knowledge of the public key and the library. The resulting output may cause an error when used in other operations; for instance, verification of a valid signature under a decompressed public key may fail. This may be leveraged by an attacker to cause an error scenario in applications which use the library, resulting in a limited denial of service for an individu

CVE-2022-36781
ScreenConnect General
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.

CVE-2022-23003
Sweet B Library General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-703 1 PoC

When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output may cause an error when used in other operations. This may be leveraged by an attacker to cause an error scenario or incorrect choice of session key in applications which use the library, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components.

CVE-2022-3175
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-756 1 PoC

Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.

CVE-2022-0122
digitalbazaar/forge General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

forge is vulnerable to URL Redirection to Untrusted Site

CVE-2022-3523
Kernel General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-119 1 PoC

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211020.

CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.