5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21349
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u321, 8u311; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: T

CVE-2022-3148
jgraph/drawio Web
5.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.

CVE-2022-2461
Transposh WordPress Translation Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
16.9%
2022 CWE-862 2 PoCs

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.

CVE-2022-21426
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle Gr

CVE-2022-42128
Software Genérico Web
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.

CVE-2022-22289
S Assistant General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

CVE-2022-4539
Web Application Firewall – website security Web Networking Windows
5.3
MEDIUM
EPSS
5.1%
2022 CWE-348 1 PoC

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.

CVE-2022-0776
hakimel/reveal.js Web ⚡ nuclei
5.3
MEDIUM
EPSS
20.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.

CVE-2022-50787
Impact/Pulse/First Web
5.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions without authentication.

CVE-2022-30076
Software Genérico General
5.3
MEDIUM
EPSS
12.4%
2022 1 PoC

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

CVE-2022-25918
shescape General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.

CVE-2022-46354
SCALANCE X204RNA (HSR) General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances.

CVE-2022-21364
PeopleSoft Enterprise PT PeopleTools Web Database
5.3
MEDIUM
EPSS
0.9%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-35948
undici Web
5.3
MEDIUM
EPSS
0.2%
2022 CWE-93 3 PoCs

undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://loc

CVE-2022-4366
lirantal/daloradius General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.

CVE-2022-33901
MultiSafepay plugin for WooCommerce (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
10.2%
2022 0 PoCs

Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

CVE-2022-24373
react-native-reanimated General
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.

CVE-2022-21302
MySQL Server Database
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-25927
ua-parser-js General
5.3
MEDIUM
EPSS
1.5%
2022 CWE-1333 2 PoCs

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.