5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28782
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2022 CWE-424 1 PoC

Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.

CVE-2022-29548
Software Genérico Web ⚡ nuclei
4.6
MEDIUM
EPSS
76.4%
2022 3 PoCs

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.

CVE-2022-39050
OTRS Web Windows
4.6
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVE-2022-21338
Communications Convergence Web Database
4.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: General Framework). The supported version that is affected is 3.0.2.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as unauthorized rea

CVE-2022-3205
Red Hat Ansible Automation Platform 1.2 DevOps Web
4.6
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

CVE-2022-2871
notrinos/notrinoserp Web
4.6
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.

CVE-2022-28196
Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 NX, Jetson TX2 series General
4.6
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.

CVE-2022-20660
Cisco Session Initiation Protocol (SIP) Software Networking
4.6
MEDIUM
EPSS
0.1%
2022 CWE-312 2 PoCs

A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on an affected device. An attacker could exploit this vulnerability by physically extracting and accessing one of the flash memory chips. A successful exploit could allow the attacker to obtain confidential information from the device, which could be used for subsequent attacks.

CVE-2022-4562
Meks Flexible Shortcodes Web Windows
4.6
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-48429
Hub Web
4.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVE-2022-30574
TIBCO FTL - Community Edition General
4.6
MEDIUM
EPSS
0.0%
2022 1 PoC

The ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, TIBCO eFTL - Enterprise Edition, and TIBCO eFTL - Enterprise Edition contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to obtain user credentials to the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.0.0 through 6.8.0, TIBCO FTL - Developer Edition: ver

CVE-2022-3439
ikus060/rdiffweb General
4.5
MEDIUM
EPSS
0.5%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

CVE-2022-0238
phoronix-test-suite/phoronix-test-suite Web
4.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-39277
glpi Web
4.5
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a Cross-Site Scripting (XSS) attack. This issue has been patched, please upgrade to GLPI 10.0.4. There are currently no known workarounds.

CVE-2022-1984
HYPR Windows WFA Windows
4.5
MEDIUM
EPSS
0.1%
2022 CWE-502 1 PoC

This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.

CVE-2022-3327
ikus060/rdiffweb General
4.5
MEDIUM
EPSS
0.3%
2022 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

CVE-2022-36840
Samsung Update Setup General
4.5
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

CVE-2022-36845
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-36329
My Cloud Home and My Cloud Home Duo Cloud
4.4
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.