5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-35066
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

CVE-2022-28749
On-Premise Meeting Connectors General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of the host.

CVE-2022-4159
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
1.0%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3677
Advanced Import : One Click Import for WordPress or Theme Demo Data Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks

CVE-2022-44267
Software Genérico General
6.5
MEDIUM
EPSS
22.1%
2022 1 PoC

ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

CVE-2022-39902
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

CVE-2022-2401
Mattermost Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

CVE-2022-3873
jgraph/drawio Web
6.5
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2.

CVE-2022-23061
Shopizer General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-639 1 PoC

In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.

CVE-2022-35062
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0bc3.

CVE-2022-35032
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.

CVE-2022-1511
snipe/snipe-it General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

CVE-2022-4152
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.9%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-0905
go-gitea/gitea General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.

CVE-2022-0524
publify/publify General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

CVE-2022-3879
Car Dealer (Dealership) and Vehicle sales WordPress Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-45894
Software Genérico General
6.5
MEDIUM
EPSS
0.7%
2022 1 PoC

GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.

CVE-2022-41296
Db2U Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.

CVE-2022-0339
janeczku/calibre-web General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.

CVE-2022-35046
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0466.