5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-39885
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

CVE-2022-28541
Samsung Update General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.

CVE-2022-36874
Waterplugin General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.

CVE-2022-25871
querymen Web
5.9
MEDIUM
EPSS
0.3%
2022 2 PoCs

All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).

CVE-2022-33729
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-21580
Financial Services Revenue Management and Billing Web Database
5.9
MEDIUM
EPSS
0.5%
2022 1 PoC

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 2.9.0.0.0, 2.9.0.1.0, 3.0.0.0.0-3.2.0.0.0 and 4.0.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or

CVE-2022-36861
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

CVE-2022-32208
https://github.com/curl/curl Web
5.9
MEDIUM
EPSS
0.1%
2022 CWE-840 1 PoC

When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

CVE-2022-30623
Chcnav - P5E GNSS General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-288 1 PoC

The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.

CVE-2022-21475
Banking Payments Web Database
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Payments accessible data as well as unauthorized read access

CVE-2022-45483
Lazy Mouse General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-40693
SDS-3008 Series Industrial Ethernet Switch General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-319 2 PoCs

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2022-36868
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-43979
Pandora FMS Web
5.9
MEDIUM
EPSS
2.0%
2022 CWE-434 1 PoC

There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user has inserted does not contain malicious characteres, but this check is insufficient. An attacker could insert an absolute path to overcome the heck, thus being able to incluse any PHP file that resides on the disk. The exploitation of this vulnerability could lead to a remote code execution.

CVE-2022-26096
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-40897
Software Genérico General
5.9
MEDIUM
EPSS
0.5%
2022 1 PoC

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVE-2022-21581
Banking Trade Finance Web Database
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-34716
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) General
5.9
MEDIUM
EPSS
1.0%
2022 1 PoC

.NET Spoofing Vulnerability

CVE-2022-43594
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

CVE-2022-39876
Reminder General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-532 1 PoC

Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.