5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-50896
Testa Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.

CVE-2022-33731
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

CVE-2022-50908
Mailhog Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads to execute arbitrary API calls, including message deletion and browser manipulation.

CVE-2022-39855
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

CVE-2022-50685
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVE-2022-50891
Owlfiles File Manager Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScript in users' browsers.

CVE-2022-28775
Samsung Flow General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.

CVE-2022-50681
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers.

CVE-2022-50804
JF511-TV Web Networking
5.1
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.

CVE-2022-50802
ETAP Safety Manager Web
5.1
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials or performing unauthorized actions.

CVE-2022-4647
microweber/microweber Web
5.1
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-50952
Banco Guayaquil Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Name Profile input. Attackers can inject malicious script code through a POST request that executes on application review without user interaction.

CVE-2022-39875
Samsung Account General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

CVE-2022-34758
Easergy P5 General
5.1
MEDIUM
EPSS
0.3%
2022 CWE-20 1 PoC

A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. Affected Products: Easergy P5 (V01.401.102 and prior)

CVE-2022-50684
Xperience General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.

CVE-2022-42895
Linux Kernel Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-824 1 PoC

There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit  https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url

CVE-2022-50941
BootCommerce General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to session hijacking, phishing attacks, and application module manipulation.

CVE-2022-1934
mruby/mruby General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-30731
My Files General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.

CVE-2022-50797
Stripe Green Downloads Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.