5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46875
Firefox General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVE-2022-3930
Directorist Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVE-2022-0579
snipe/snipe-it General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

CVE-2022-34366
SupportAssist Client Consumer General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-942 1 PoC

Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

CVE-2022-1287
School Club Application System Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-99 1 PoC

A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalation. The attack can be initiated remotely and does not require authentication. The exploit has been disclosed to the public and may be used.

CVE-2022-30585
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to view sensitive information. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVE-2022-2449
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site.

CVE-2022-37050
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

CVE-2022-0859
McAfee ePolicy Orchestrator (ePO) Database
6.5
MEDIUM
EPSS
0.0%
2022 CWE-522 1 PoC

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server (restricted to administrators) and to know the SQL server password.

CVE-2022-42282
NVIDIA DGX servers Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

CVE-2022-2402
ESET Endpoint Encryption General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-121 2 PoCs

The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

CVE-2022-35040
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b5567.

CVE-2022-0955
pimcore/data-hub Web
6.5
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.

CVE-2022-29888
InRouter302 Web Networking
6.5
MEDIUM
EPSS
1.5%
2022 CWE-489 1 PoC

A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-24729
ckeditor4 General
6.5
MEDIUM
EPSS
0.8%
2022 CWE-400 2 PoCs

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVE-2022-4868
froxlor/froxlor General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVE-2022-0766
janeczku/calibre-web General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVE-2022-28689
InRouter302 Networking
6.5
MEDIUM
EPSS
0.5%
2022 CWE-489 1 PoC

A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-36317
Firefox General
6.5
MEDIUM
EPSS
0.3%
2022 2 PoCs

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVE-2022-21601
Communications Billing and Revenue Management Database
6.5
MEDIUM
EPSS
1.1%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a partial denial of serv