5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4240
OneWireless General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 1 PoC

Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1

CVE-2022-40959
Firefox ESR General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVE-2022-35047
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05aa.

CVE-2022-4016
Booster for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks

CVE-2022-44008
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-end Tomcat server directly.

CVE-2022-35049
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b03b5.

CVE-2022-28760
Zoom On-Premise Meeting Connector MMR General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-3883
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-35061
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.

CVE-2022-36779
PROSCEND M330-w / M330-W5 Web Networking
6.5
MEDIUM
EPSS
23.2%
2022 5 PoCs

PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html https://cdn.shopify.com/s/files/1/0036/9413/3297/files/ADVICE_Industrial_4G_LTE_Cellular_Router_ICR111WG.pdf?v=1620814301

CVE-2022-29916
Thunderbird General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVE-2022-3247
Blog2Social: Social Media Auto Post & Scheduler Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 CWE-918 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

CVE-2022-35039
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.

CVE-2022-30570
TIBCO Data Virtualization Cloud
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with network access to obtain read access to application information on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 8.5.2 and below and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.2 and below.

CVE-2022-3882
Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-0623
mruby/mruby General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-125 1 PoC

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-34661
Teamcenter V12.4 General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-835 1 PoC

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter is vulnerable to denial of service by entering infinite loops and using up CPU cycles. This could allow an attacker to cause denial of service condition.

CVE-2022-40982
Intel(R) Processors General
6.5
MEDIUM
EPSS
0.7%
2022 1 PoC

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-45962
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.

CVE-2022-34125
Software Genérico Web
6.5
MEDIUM
EPSS
9.4%
2022 1 PoC

front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.