5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28776
Galaxy Store General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.

CVE-2022-26093
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-21474
Banking Trade Finance Web Database
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-21541
Java SE JDK and JRE Database
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle J

CVE-2022-26097
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-20738
Cisco Umbrella Insights Virtual Appliance Networking
5.8
MEDIUM
EPSS
1.3%
2022 CWE-693 1 PoC

A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypass the file inspection feature. This vulnerability is due to insufficient restrictions in the file inspection feature. An attacker could exploit this vulnerability by downloading a crafted payload through specific methods. A successful exploit could allow the attacker to bypass file inspection protections and download a malicious payload.

CVE-2022-26948
Software Genérico General
5.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.

CVE-2022-20795
Cisco Adaptive Security Appliance (ASA) Software Networking
5.8
MEDIUM
EPSS
0.4%
2022 CWE-345 1 PoC

A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processing that occurs when establishing a DTLS tunnel as part of an AnyConnect SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted DTLS traffic to an affected device. A successful exploit could allow the

CVE-2022-21508
Hyperion Essbase Database
5.8
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Essbase executes to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Essbase accessible data as well as unauthorized access to critical data or complete access to all

CVE-2022-43473
OpManager General
5.8
MEDIUM
EPSS
35.6%
2022 CWE-611 1 PoC

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

CVE-2022-3211
pimcore/pimcore Web
5.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.

CVE-2022-2196
Linux Kernel General
5.8
MEDIUM
EPSS
0.0%
2022 CWE-1188 1 PoC

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit 2e7eab81425a

CVE-2022-45835
PhonePe Payment Solutions General ⚡ nuclei
5.8
MEDIUM
EPSS
71.1%
2022 CWE-918 0 PoCs

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

CVE-2022-0507
Pandora FMS Web Database
5.8
MEDIUM
EPSS
0.4%
2022 CWE-89 2 PoCs

Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

CVE-2022-22284
Samsung Internet General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

CVE-2022-24926
SmartTagPlugin Web
5.7
MEDIUM
EPSS
0.4%
2022 CWE-20 1 PoC

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

CVE-2022-0505
microweber/microweber Web
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-3516
librenms/librenms Web
5.7
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-4719
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.4%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

CVE-2022-0407
vim/vim General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.