5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-26951
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.

CVE-2022-22948
🔥 KEV VMware vCenter Server and VMware Cloud Foundation Cloud
6.5
MEDIUM
EPSS
26.0%
2022 3 PoCs

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

CVE-2022-46695
tvOS General
6.5
MEDIUM
EPSS
0.8%
2022 5 PoCs

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.

CVE-2022-4888
Checkout Fields Manager Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts WordPress plugin before 1.0.2, Gift Registry for WooCommerce WordPress plugin through 1.0.1, Image Watermark for WooCommerce WordPress plugin before 1.0.1, Order Approval for WooCommerce WordPress plugin before 1.1.0, Order Tracking for WooCommerce WordPress plugin before 1.0.2, Price Ca

CVE-2022-41274
Disclosure Management General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-863 1 PoC

SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can lead to the exposure of data like financial reports.

CVE-2022-4160
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.8%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-21350
WebLogic Server Database
6.5
MEDIUM
EPSS
46.2%
2022 2 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (I

CVE-2022-35037
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.

CVE-2022-20816
Cisco Unified Communications Manager Web Networking
6.5
MEDIUM
EPSS
0.7%
2022 CWE-22 1 PoC

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an affected system. This vulnerability exists because the affected software does not properly validate HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system.

CVE-2022-50980
VibroLine VLX1 HD 5.0 General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 2 PoCs

A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.

CVE-2022-0686
unshiftio/url-parse General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

CVE-2022-38970
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.

CVE-2022-50979
VibroLine VLX1 HD 5.0 General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

CVE-2022-0197
phoronix-test-suite/phoronix-test-suite Web
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-21345
PeopleSoft Enterprise PT PeopleTools Web Database
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-38072
ADMesh General
6.5
MEDIUM
EPSS
0.6%
2022 CWE-118 1 PoC

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-3097
Plugin LBstopattack Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections.

CVE-2022-4107
SMSA Shipping for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

CVE-2022-26068
pistacheio/pistache General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.

CVE-2022-2730
openemr/openemr General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.