5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2776
Gym Management System Web
5.4
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Gym Management System. Affected is an unknown function of the file delete_user.php. The manipulation of the argument delete_user leads to denial of service. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-206172.

CVE-2022-47073
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 3 PoCs

A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.

CVE-2022-4753
Print-O-Matic Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Print-O-Matic WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-0133
chocobozzz/peertube General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

peertube is vulnerable to Improper Access Control

CVE-2022-2585
linux General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-416 4 PoCs

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

CVE-2022-41988
OpenImageIO General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-21602
PeopleSoft Enterprise PT PeopleTools Web Database
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-21305
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition acces

CVE-2022-22496
Spectrum Protect Server General
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.

CVE-2022-30622
Chcnav - P5E GNSS Web
5.3
MEDIUM
EPSS
0.0%
2022 2 PoCs

Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_username_passwd.cmd - The server loads the request clearly by default. Disclosure of hard-coded credit information within the JS code sent to the customer within the Login.js file is a strong user (which is not documented) and also the password, which allow for super-user access. Username: chcadmin, Password: chcpassword.

CVE-2022-46371
AR7088H-A General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.

CVE-2022-3222
gpac/gpac General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-674 2 PoCs

Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-0689
microweber/microweber General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-840 1 PoC

Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-25858
terser General
5.3
MEDIUM
EPSS
3.6%
2022 2 PoCs

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

CVE-2022-42257
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.3
MEDIUM
EPSS
0.0%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service.

CVE-2022-1815
jgraph/drawio General ⚡ nuclei
5.3
MEDIUM
EPSS
24.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

CVE-2022-23001
Sweet B Library General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-682 1 PoC

When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user level privileges and no other user's assistance can exploit this vulnerability with only knowledge of the public key and the library. The resulting output may cause an error when used in other operations; for instance, verification of a valid signature under a decompressed public key may fail. This may be leveraged by an attacker to cause an error scenario in applications which use the library, resulting in a limited denial of service for an individu

CVE-2022-25758
scss-tokenizer General
5.3
MEDIUM
EPSS
0.5%
2022 2 PoCs

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVE-2022-45354
Download Monitor General ⚡ nuclei
5.3
MEDIUM
EPSS
87.6%
2022 CWE-200 2 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.