5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1196
Thunderbird General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.

CVE-2022-26135
Jira Core Server General
6.5
MEDIUM
EPSS
89.3%
2022 1 PoC

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

CVE-2022-2188
DXL Broker General
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.

CVE-2022-0624
ionicabizau/parse-path General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.

CVE-2022-1223
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-35041
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b558f.

CVE-2022-38749
SnakeYAML General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-39901
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

CVE-2022-0639
unshiftio/url-parse General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

CVE-2022-25937
glance Web
6.5
MEDIUM
EPSS
0.7%
2022 CWE-22 2 PoCs

Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).

CVE-2022-3961
Directorist Web Windows
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.

CVE-2022-30614
Cognos Analytics General
6.5
MEDIUM
EPSS
1.3%
2022 1 PoC

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.

CVE-2022-24865
humhub General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue.

CVE-2022-2130
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
46.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2022-45133
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file could allow one to traverse the server to obtain access to secure files or cause code execution based on the payload.

CVE-2022-2330
DLP Endpoint for Windows General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-611 1 PoC

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

CVE-2022-25645
dset General
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVE-2022-2174
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
27.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

CVE-2022-31629
PHP Web
6.5
MEDIUM
EPSS
15.4%
2022 CWE-20 2 PoCs

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVE-2022-37424
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.