7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0928
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
6.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-36325
RUGGEDCOM RM1224 LTE(4G) EU Web
6.8
MEDIUM
EPSS
0.4%
2022 CWE-80 1 PoC

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

CVE-2022-4759
GigPress Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-39051
OTRS General
6.8
MEDIUM
EPSS
0.5%
2022 CWE-913 1 PoC

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

CVE-2022-30624
Chcnav - P5E GNSS General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.

CVE-2022-46367
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.

CVE-2022-28542
Galaxy Store General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.

CVE-2022-21551
GoldenGate Web Database
6.8
MEDIUM
EPSS
1.6%
2022 1 PoC

Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate). The supported version that is affected is 21c: prior to 21.7.0.0.0; 19c: prior to 19.1.0.0.220719. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CVE-2022-46368
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2022-3267
ikus060/rdiffweb Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.

CVE-2022-0158
vim/vim General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-29828
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.5%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project file or execute programs illegally.

CVE-2022-0911
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-4471
YARPP Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-22997
My Cloud Home Cloud
6.8
MEDIUM
EPSS
1.7%
2022 CWE-78 1 PoC

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

CVE-2022-0954
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
4.3%
2022 CWE-79 1 PoC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-41333
FortiRecorder General
6.8
MEDIUM
EPSS
30.0%
2022 CWE-400 2 PoCs

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.

CVE-2022-38451
FreshTomato Web
6.8
MEDIUM
EPSS
4.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1351
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.