7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46361
OneWireless General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-77 1 PoC

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.

CVE-2022-50956
amministrazione-aperta Web Windows
6.9
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server.

CVE-2022-50800
H3C SSL VPN Networking
6.9
MEDIUM
EPSS
0.1%
2022 CWE-203 2 PoCs

H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the login_submit.cgi endpoint and analyze response messages to distinguish between existing and non-existing accounts.

CVE-2022-50788
Impact/Pulse/First General
6.9
MEDIUM
EPSS
0.6%
2022 CWE-548 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.

CVE-2022-1401
CMDB General
6.9
MEDIUM
EPSS
5.0%
2022 CWE-863 1 PoC

Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.

CVE-2022-50686
Xperience General
6.9
MEDIUM
EPSS
0.1%
2022 CWE-209 1 PoC

An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.

CVE-2022-50790
Impact/Pulse/First General
6.9
MEDIUM
EPSS
0.4%
2022 CWE-306 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication.

CVE-2022-25842
com.alibaba.oneagent:one-java-agent-plugin General
6.9
MEDIUM
EPSS
2.7%
2022 2 PoCs

All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.

CVE-2022-0967
star7th/showdoc Web
6.9
MEDIUM
EPSS
0.8%
2022 CWE-79 2 PoCs

Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-39908
Samsung Mobile Devices General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-367 1 PoC

TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVE-2022-2589
beancount/fava Web
6.9
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.

CVE-2022-39907
Samsung Mobile Devices General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-190 1 PoC

Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVE-2022-50692
Impact/Pulse/First General
6.9
MEDIUM
EPSS
0.1%
2022 CWE-613 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized access to the application.

CVE-2022-50687
Cobian Backup Gravity General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-120 1 PoC

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.

CVE-2022-50689
Cobian Reflector General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-120 1 PoC

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.

CVE-2022-29833
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.3%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could access to MELSEC safety CPU modules illgally.

CVE-2022-28810
🔥 KEV Software Genérico General
6.8
MEDIUM
EPSS
90.7%
2022 2 PoCs

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

CVE-2022-2495
microweber/microweber Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2022-29827
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.5%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project files or execute programs illegally.

CVE-2022-1163
mineweb/minewebcms Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 3 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.