5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1617
WP-Invoice Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

CVE-2022-4329
Product list Widget for Woocommerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).

CVE-2022-4745
WP Customer Area Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

CVE-2022-46957
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Sourcecodester.com Online Graduate Tracer System V 1.0.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-38481
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

An issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP2. The application is prone to reflected Cross-site Scripting (XSS) in several features.

CVE-2022-21621
VM VirtualBox Database
6.0
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Virtua

CVE-2022-34449
PowerPath Management Appliance General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-798 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application.

CVE-2022-4605
flatpressblog/flatpress Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2022-42287
NVIDIA DGX servers General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.

CVE-2022-4314
ikus060/rdiffweb General
6.0
MEDIUM
EPSS
0.4%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.

CVE-2022-41261
Solution Manager (Diagnostic Agent) Windows
6.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation can make the attacker access files and systems for which he/she is not authorized.

CVE-2022-0915
Sync Windows
6.0
MEDIUM
EPSS
0.0%
2022 CWE-367 1 PoC

There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.

CVE-2022-34709
Windows 10 Version 1809 Windows
6.0
MEDIUM
EPSS
1.3%
2022 1 PoC

Windows Defender Credential Guard Security Feature Bypass Vulnerability

CVE-2022-31596
SAP Business Objects Platform (Monitoring DB) Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-668 1 PoC

Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal) system data which would otherwise be restricted. Also, a potential attack could be used to leave the CMS's scope and impact the database. A successful attack could have a low impact on confidentiality, a high impact on integrity, and a low impact on availability.

CVE-2022-22555
PowerStore General
6.0
MEDIUM
EPSS
0.6%
2022 CWE-78 2 PoCs

Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.

CVE-2022-21575
WebCenter Sites Web Database
6.0
MEDIUM
EPSS
0.5%
2022 1 PoC

Vulnerability in the Oracle WebCenter Sites Support Tools product of Oracle Fusion Middleware (component: User Interface). The supported version that is affected is Prior to 4.4.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites Support Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites Support Tools accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites Support Tool

CVE-2022-48682
Software Genérico General
6.0
MEDIUM
EPSS
0.0%
2022 1 PoC

In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.

CVE-2022-32493
CPG BIOS General
6.0
MEDIUM
EPSS
0.0%
2022 CWE-121 1 PoC

Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-26579
Software Genérico General
6.0
MEDIUM
EPSS
0.0%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages. The attacker must have shell access to the device and gain root privileges in order to exploit this vulnerability.

CVE-2022-39423
VM VirtualBox Database
6.0
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. C