5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38778
kibana General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-20 1 PoC

A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.

CVE-2022-43022
Software Genérico Database
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVE-2022-28287
Firefox General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.

CVE-2022-45170
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.

CVE-2022-35064
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adcdb in __asan_memset.

CVE-2022-4024
Registration Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVE-2022-45180
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).

CVE-2022-21556
MySQL Server Database
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Integrity and Availabil

CVE-2022-29914
Thunderbird General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVE-2022-43972
WRT54GL Wireless-G Broadband Router Networking
6.5
MEDIUM
EPSS
1.5%
2022 CWE-476 3 PoCs

A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.

CVE-2022-41560
TIBCO Nimbus General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Statement Set Upload via the Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Denial of Service Attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: version 10.5.0.

CVE-2022-45130
Software Genérico Web
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.

CVE-2022-1224
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-40845
Software Genérico Networking
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.

CVE-2022-3082
miniOrange Discord Integration Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

CVE-2022-47931
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

IO FinNet tss-lib before 2.0.0 allows a collision of hash values.

CVE-2022-3411
GitLab DevOps
6.5
MEDIUM
EPSS
2.3%
2022 1 PoC

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVE-2022-2368
microweber/microweber General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-290 1 PoC

Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

CVE-2022-35055
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0473.

CVE-2022-31743
Firefox General
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.