5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36318
Firefox ESR General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

CVE-2022-23716
Elastic Cloud Enterprise Cloud
5.3
MEDIUM
EPSS
0.2%
2022 CWE-532 1 PoC

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.

CVE-2022-21293
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Ent

CVE-2022-2930
octoprint/octoprint General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-22409
Aspera Faspex General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.

CVE-2022-42127
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.

CVE-2022-35739
Software Genérico Web
5.3
MEDIUM
EPSS
1.2%
2022 1 PoC

PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.

CVE-2022-0713
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

CVE-2022-36781
ScreenConnect General
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.

CVE-2022-39862
Samsung Mobile Devices Web
5.3
MEDIUM
EPSS
0.3%
2022 CWE-285 1 PoC

Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.

CVE-2022-42892
syngo Dynamics General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-23 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder accessible to the account assigned to the website’s application pool.

CVE-2022-0170
chocobozzz/peertube General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

peertube is vulnerable to Improper Access Control

CVE-2022-4429
Avira Security for Windows Windows
5.3
MEDIUM
EPSS
0.0%
2022 CWE-428 1 PoC

Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service. The issue was fixed with Avira Security version 1.1.78

CVE-2022-4097
All-In-One Security (AIOS) Web Windows
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

CVE-2022-31062
glpi-inventory-plugin Web
5.3
MEDIUM
EPSS
11.0%
2022 CWE-22 1 PoC

### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

CVE-2022-24819
xwiki-platform General ⚡ nuclei
5.3
MEDIUM
EPSS
4.3%
2022 CWE-359 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

CVE-2022-41697
Ghost Web ⚡ nuclei
5.3
MEDIUM
EPSS
18.6%
2022 CWE-204 1 PoC

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2022-4417
WP Cerber Security, Anti-spam & Malware Scan Web Windows
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users

CVE-2022-40482
Software Genérico Web
5.3
MEDIUM
EPSS
0.5%
2022 1 PoC

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.