5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21439
Solaris Operating System Database
4.2
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.2 (Availability impacts). CVSS Vector: (CVSS

CVE-2022-21555
MySQL Server Database
4.2
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the MySQL Shell for VS Code product of Oracle MySQL (component: Shell: GUI). Supported versions that are affected are 1.1.8 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Shell for VS Code executes to compromise MySQL Shell for VS Code. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Shell for VS Code, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauth

CVE-2022-25778
GateManager Web
4.2
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

CVE-2022-25869
angular Web
4.2
MEDIUM
EPSS
5.8%
2022 CWE-79 12 PoCs

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

CVE-2022-39404
MySQL Installer Database
4.2
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Supported versions that are affected are 1.6.3 and prior. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Installer executes to compromise MySQL Installer. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Installer accessible data as well as unauthorized read access to a subset of MySQL Ins

CVE-2022-4808
usememos/memos General
4.2
MEDIUM
EPSS
0.2%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-0705
pimcore/pimcore Web
4.2
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-25781
GateManager Web
4.2
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.

CVE-2022-29839
My Cloud Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2022-0414
dolibarr/dolibarr General
4.1
MEDIUM
EPSS
0.3%
2022 CWE-1284 1 PoC

Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.

CVE-2022-32491
CPG BIOS General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-119 1 PoC

Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.

CVE-2022-28192
NVIDIA Virtual GPU Software and NVIDIA Cloud Gaming Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

CVE-2022-30740
Samsung Internet General
4.1
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

CVE-2022-25816
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

CVE-2022-21611
MySQL Server Database
4.1
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.30 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-2870
laravel Web
4.1
MEDIUM
EPSS
0.4%
2022 CWE-502 1 PoC

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

CVE-2022-24929
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-926 1 PoC

Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

CVE-2022-25817
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.

CVE-2022-30724
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-39894
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.