1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3590
WordPress Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
90.8%
2022 4 PoCs

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVE-2022-3881
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log Web Windows
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-22323
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 218379.

CVE-2022-2355
Easy Username Updater Web Windows
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin

CVE-2022-22312
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

CVE-2022-2473
WP-UserOnline Web Windows
5.5
MEDIUM
EPSS
1.0%
2022 CWE-79 3 PoCs

The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The only affects multi-site installations and installations where unfiltered_html is disabled.

CVE-2022-34712
Windows 10 Version 21H1 Windows
5.5
MEDIUM
EPSS
4.2%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-21533
Solaris Operating System Database Windows
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMB Server). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-28189
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NULL pointer dereference may lead to a system crash.

CVE-2022-46692
iCloud for Windows Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2022 5 PoCs

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

CVE-2022-3690
Popup Maker Web Windows
5.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins

CVE-2022-34710
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.7%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-34683
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 2 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.

CVE-2022-24483
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
5.9%
2022 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2022-41205
SAP GUI for Windows Windows
5.5
MEDIUM
EPSS
0.2%
2022 CWE-94 1 PoC

SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.

CVE-2022-34708
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2022 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2022-34681
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.

CVE-2022-30155
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2022 1 PoC

Windows Kernel Denial of Service Vulnerability

CVE-2022-36314
Firefox ESR Windows
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.

CVE-2022-21877
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
15.0%
2022 1 PoC

Storage Spaces Controller Information Disclosure Vulnerability