5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22312
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

CVE-2022-30625
Chcnav - P5E GNSS General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-548 1 PoC

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

CVE-2022-39899
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

CVE-2022-3881
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log Web Windows
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-21557
WebLogic Server DevOps Database
5.7
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete acc

CVE-2022-0268
getgrav/grav Web
5.7
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.

CVE-2022-36859
SmartTagPlugin Web
5.7
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim's devices.

CVE-2022-26091
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.

CVE-2022-4331
GitLab DevOps
5.7
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVE-2022-0963
microweber/microweber Web ⚡ nuclei
5.7
MEDIUM
EPSS
8.3%
2022 CWE-79 1 PoC

Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-30627
Chcnav - P5E GNSS General
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the existing user passwords on their operating systems and passwords.

CVE-2022-38124
SiteManager General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-267 1 PoC

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

CVE-2022-1648
Pandora FMS Web
5.7
MEDIUM
EPSS
2.8%
2022 CWE-23 1 PoC

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.

CVE-2022-0231
livehelperchat/livehelperchat Web
5.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-21609
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessi

CVE-2022-3290
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-130 1 PoC

Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-2549
gpac/gpac General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-2355
Easy Username Updater Web Windows
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin

CVE-2022-3438
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

CVE-2022-28195
Jetson AGX Xavier series, Jetson Xavier NX General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.