5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-35925
bookwyrm Web
5.3
MEDIUM
EPSS
0.5%
2022 CWE-287 1 PoC

BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has been patched in version 0.4.5. Admins with existing instances will need to update their `nginx.conf` file that was created when the instance was set up. Users are advised advised to upgrade. Users unable to upgrade may update their nginx.conf files with the changes manually.

CVE-2022-3295
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-30515
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

CVE-2022-21628
Java SE JDK and JRE Web Database
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java S

CVE-2022-22120
nocodb General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-203 1 PoC

In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.

CVE-2022-4346
All-In-One Security (AIOS) Web Windows
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.

CVE-2022-0668
JFrog Artifactory General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-274 1 PoC

JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.

CVE-2022-21616
WebLogic Server DevOps Database
5.2
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracl

CVE-2022-39262
glpi General
5.2
MEDIUM
EPSS
0.3%
2022 CWE-83 1 PoC

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrator can define rich-text content to be displayed on login page. The displayed content is can contains malicious code that can be used to steal credentials. This issue has been patched, please upgrade to version 10.0.4.

CVE-2022-0157
phoronix-test-suite/phoronix-test-suite Web
5.2
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-43980
Pandora FMS Web
5.2
MEDIUM
EPSS
0.3%
2022 CWE-352 2 PoCs

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.

CVE-2022-41210
SAP Customer Data Cloud (Gigya) Cloud
5.2
MEDIUM
EPSS
0.1%
2022 CWE-338 1 PoC

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.

CVE-2022-41209
SAP Customer Data Cloud (Gigya) Cloud
5.2
MEDIUM
EPSS
0.0%
2022 CWE-326 1 PoC

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.

CVE-2022-26581
Software Genérico General
5.2
MEDIUM
EPSS
0.1%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2022-4979
Experience Platform Web Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.

CVE-2022-50951
WiFi File Transfer Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through file and folder names. Attackers can exploit the web server's input validation weakness to execute arbitrary JavaScript when users preview infected file paths, potentially compromising user browser sessions.

CVE-2022-50940
Knap Advanced PHP Login Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script code in the name parameter. Attackers can exploit the vulnerability to execute arbitrary scripts in users and activity log backend modules, potentially leading to session hijacking and persistent phishing attacks.

CVE-2022-45478
Telepad General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-33695
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-732 1 PoC

Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

CVE-2022-36848
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.