5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21401
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-0341
vanessa219/vditor Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.

CVE-2022-27822
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

CVE-2022-0262
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

CVE-2022-25785
SiteManager General
6.6
MEDIUM
EPSS
1.1%
2022 CWE-121 1 PoC

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVE-2022-21363
MySQL Connectors Database
6.6
MEDIUM
EPSS
1.0%
2022 1 PoC

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-1534
bfabiszewski/libmobi General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-126 1 PoC

Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

CVE-2022-0285
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

CVE-2022-0838
hestiacp/hestiacp Web
6.6
MEDIUM
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

CVE-2022-1733
vim/vim General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.

CVE-2022-21210
lansweeper Web Database
6.6
MEDIUM
EPSS
6.7%
2022 CWE-89 2 PoCs

An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-1796
vim/vim General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 8.2.4979.

CVE-2022-0509
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

CVE-2022-1296
radareorg/radare2 General
6.6
MEDIUM
EPSS
0.3%
2022 CWE-125 1 PoC

Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

CVE-2022-1207
radareorg/radare2 General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.

CVE-2022-3294
Kubernetes DevOps Web
6.6
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server'

CVE-2022-1720
vim/vim General
6.6
MEDIUM
EPSS
0.5%
2022 CWE-126 4 PoCs

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVE-2022-2874
vim/vim General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0224.

CVE-2022-1620
vim/vim General
6.6
MEDIUM
EPSS
0.5%
2022 CWE-476 2 PoCs

NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.

CVE-2022-2777
microweber/microweber Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.