7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3255
pimcore/pimcore General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.

CVE-2022-2495
microweber/microweber Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2022-3278
vim/vim General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.

CVE-2022-39187
FTP server Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors.

CVE-2022-0893
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-0213
vim/vim General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-1554
clinical-genomics/scout General
6.8
MEDIUM
EPSS
0.6%
2022 CWE-36 1 PoC

Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.

CVE-2022-33730
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-787 1 PoC

Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.

CVE-2022-22997
My Cloud Home Cloud
6.8
MEDIUM
EPSS
1.7%
2022 CWE-78 1 PoC

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

CVE-2022-1726
wenzhixin/bootstrap-table Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVE-2022-39051
OTRS General
6.8
MEDIUM
EPSS
0.5%
2022 CWE-913 1 PoC

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

CVE-2022-4793
Blog Designer Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4764
Simple File Downloader Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-39913
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2022-30624
Chcnav - P5E GNSS General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.

CVE-2022-0695
radareorg/radare2 General
6.8
MEDIUM
EPSS
0.3%
2022 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-47632
Software Genérico Windows
6.8
MEDIUM
EPSS
0.1%
2022 5 PoCs

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write access for the SYSTEM user. Although the service will not start if the malicious DLLs are unsigned, it suffices to use self-signed DLLs. The validity of the DLL signatures is not checked. As a result, local Windows users can abuse the Razer driver installer to obtain administrativ

CVE-2022-4645
libtiff General
6.8
MEDIUM
EPSS
0.0%
2022 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

CVE-2022-33165
Security Directory Server General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.