5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-39187
FTP server Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors.

CVE-2022-33730
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-787 1 PoC

Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.

CVE-2022-0695
radareorg/radare2 General
6.8
MEDIUM
EPSS
0.3%
2022 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-4293
vim/vim General
6.8
MEDIUM
EPSS
0.3%
2022 CWE-1077 1 PoC

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

CVE-2022-0020
Cortex XSOAR Web Networking
6.8
MEDIUM
EPSS
1.0%
2022 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

CVE-2022-33165
Security Directory Server General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.

CVE-2022-4645
libtiff General
6.8
MEDIUM
EPSS
0.0%
2022 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

CVE-2022-4793
Blog Designer Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-1726
wenzhixin/bootstrap-table Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVE-2022-0929
microweber/microweber Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-1554
clinical-genomics/scout General
6.8
MEDIUM
EPSS
0.6%
2022 CWE-36 1 PoC

Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.

CVE-2022-4761
Post Views Count (Support caching plugins!) Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-41564
TIBCO Hawk General
6.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO Operational Intelligence Hawk RedTail: versions 7.0.0 through 7.2.0.

CVE-2022-28810
🔥 KEV Software Genérico General
6.8
MEDIUM
EPSS
90.7%
2022 2 PoCs

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

CVE-2022-34660
Teamcenter V12.4 General
6.8
MEDIUM
EPSS
0.9%
2022 CWE-77 1 PoC

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter consist of a functionality that is vulnerable to command injection. This could potentially allow an attacker to perform remote code execution.

CVE-2022-47632
Software Genérico Windows
6.8
MEDIUM
EPSS
0.1%
2022 5 PoCs

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write access for the SYSTEM user. Although the service will not start if the malicious DLLs are unsigned, it suffices to use self-signed DLLs. The validity of the DLL signatures is not checked. As a result, local Windows users can abuse the Razer driver installer to obtain administrativ

CVE-2022-0213
vim/vim General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-22997
My Cloud Home Cloud
6.8
MEDIUM
EPSS
1.7%
2022 CWE-78 1 PoC

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

CVE-2022-46368
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

CVE-2022-1631
microweber/microweber General
6.8
MEDIUM
EPSS
11.7%
2022 CWE-284 2 PoCs

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would