5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-35136
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

CVE-2022-35026
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.

CVE-2022-2290
zadam/trilium Web ⚡ nuclei
6.4
MEDIUM
EPSS
7.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.

CVE-2022-32506
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-3269
ikus060/rdiffweb General
6.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

CVE-2022-4470
Widgets for Google Reviews Web Windows
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21579
FLEXCUBE Universal Banking Web Database
6.4
MEDIUM
EPSS
1.5%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Bankin

CVE-2022-23431
Samsung Mobile Devices with Exynos chipsets General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-120 1 PoC

An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

CVE-2022-40634
Crafter CMS Web
6.4
MEDIUM
EPSS
14.5%
2022 CWE-913 1 PoC

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.

CVE-2022-34387
SupportAssist General
6.4
MEDIUM
EPSS
0.1%
2022 CWE-377 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.

CVE-2022-2965
notrinos/notrinoserp General
6.4
MEDIUM
EPSS
0.3%
2022 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.

CVE-2022-23540
node-jsonwebtoken General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the `jwt.verify()` function. This issue has been fixed, please update to version 9.0.0 which removes the default support for the none algorithm in the `jwt.verify()` method. There will be no impact, if you update to version 9.0.0 and you don’t need to allow for the `none` algorithm. If you need 'none' algorithm, you have to

CVE-2022-39854
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

CVE-2022-21381
Enterprise Session Border Controller Web Database
6.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. While the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Con

CVE-2022-4138
GitLab DevOps
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVE-2022-47373
Pandora FMS Web
6.4
MEDIUM
EPSS
0.7%
2022 CWE-352 2 PoCs

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.

CVE-2022-0966
star7th/showdoc Web
6.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.

CVE-2022-21584
Banking Trade Finance Web Database
6.4
MEDIUM
EPSS
1.5%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-41545
Software Genérico Web Networking
6.4
MEDIUM
EPSS
0.0%
2022 1 PoC

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.

CVE-2022-23432
Samsung Mobile Devices with Exynos chipsets General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.