5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1769
vim/vim General
6.6
MEDIUM
EPSS
0.2%
2022 CWE-126 2 PoCs

Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.

CVE-2022-21403
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-20828
Cisco FirePOWER Services Software for ASA Web Networking
6.5
MEDIUM
EPSS
53.0%
2022 CWE-236 1 PoC

A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper handling of undefined command parameters. An attacker could exploit this vulnerability by using a crafted command on the CLI or by submitting a crafted HTTPS request to the web-based management interface of the Cisco ASA that is hosting the ASA FirePOWER module. Note: To exploit

CVE-2022-41258
SAP Financial Consolidation General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality, integrity and availability of the application.

CVE-2022-23253
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
30.2%
2022 1 PoC

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

CVE-2022-2762
AdminPad Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack

CVE-2022-4151
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-4011
Simple History Plugin General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-707 1 PoC

A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213785 was assigned to this vulnerability.

CVE-2022-34365
Wyse Management Suite Web
6.5
MEDIUM
EPSS
0.5%
2022 CWE-22 1 PoC

WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

CVE-2022-3880
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-41259
SAP SQL Anywhere Database
6.5
MEDIUM
EPSS
0.6%
2022 CWE-89 1 PoC

SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.

CVE-2022-35050
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b04de.

CVE-2022-35054
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.

CVE-2022-1185
GitLab DevOps
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVE-2022-22748
Firefox ESR General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVE-2022-33925
Wyse Management Suite General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.

CVE-2022-35058
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05ce.

CVE-2022-35022
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.

CVE-2022-32199
Software Genérico Web
6.5
MEDIUM
EPSS
13.1%
2022 1 PoC

db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file parameter.

CVE-2022-3762
Booster for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.8%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the server even when they are not supposed to be able to (for example in multisite)