5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-35507
Software Genérico Web ⚡ nuclei
4.3
MEDIUM
EPSS
14.3%
2022 1 PoC

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

CVE-2022-39419
Database - Enterprise Edition Database
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java VM accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-25780
GateManager General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope.

CVE-2022-29974
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in certain ASUS devices.

CVE-2022-1193
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVE-2022-3813
Bento4 General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212679.

CVE-2022-36315
Firefox General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.

CVE-2022-38756
Micro Focus GroupWise Web Web
4.3
MEDIUM
EPSS
0.2%
2022 3 PoCs

A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

CVE-2022-39888
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2022 1 PoC

Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

CVE-2022-2704
Simple E-Learning System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205828.

CVE-2022-4738
Blood Bank Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-216774 is the identifier assigned to this vulnerability.

CVE-2022-3524
Kernel General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-404 1 PoC

A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this vulnerability.

CVE-2022-3810
Bento4 General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212667.

CVE-2022-21243
Primavera Portfolio Management Web Database
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Portfolio Management. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV

CVE-2022-3242
microweber/microweber General ⚡ nuclei
4.3
MEDIUM
EPSS
19.8%
2022 CWE-94 1 PoC

Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-0560
microweber/microweber General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-601 1 PoC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-1982
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

CVE-2022-30738
Samsung Internet General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-703 1 PoC

Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.

CVE-2022-24403
TETRA Standard General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-327 1 PoC

The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known encrypted/unencrypted identity pairs.

CVE-2022-42126
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.