7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-34660
Teamcenter V12.4 General
6.8
MEDIUM
EPSS
0.9%
2022 CWE-77 1 PoC

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter consist of a functionality that is vulnerable to command injection. This could potentially allow an attacker to perform remote code execution.

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2022-0020
Cortex XSOAR Web Networking
6.8
MEDIUM
EPSS
1.0%
2022 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

CVE-2022-0571
phoronix-test-suite/phoronix-test-suite Web
6.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.

CVE-2022-38451
FreshTomato Web
6.8
MEDIUM
EPSS
4.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-28185
NVIDIA GPU Display Driver Windows
6.8
MEDIUM
EPSS
0.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.

CVE-2022-0213
vim/vim General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-4471
YARPP Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-3349
PS4 General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-119 1 PoC

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

CVE-2022-47930
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofing of messages easier. In particular, the Schnorr proof of knowledge implemented in sch.go does not utilize a session id, context, or random nonce in the generation of the challenge. This could allow a malicious user or an eavesdropper to replay a valid proof sent in the past.

CVE-2022-39051
OTRS General
6.8
MEDIUM
EPSS
0.5%
2022 CWE-913 1 PoC

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

CVE-2022-31898
Software Genérico General
6.8
MEDIUM
EPSS
22.4%
2022 2 PoCs

gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.

CVE-2022-1631
microweber/microweber General
6.8
MEDIUM
EPSS
11.7%
2022 CWE-284 2 PoCs

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would

CVE-2022-2016
neorazorx/facturascripts Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.

CVE-2022-0717
mruby/mruby General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-0156
vim/vim General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2022-0954
microweber/microweber Web ⚡ nuclei
6.8
MEDIUM
EPSS
4.3%
2022 CWE-79 1 PoC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-41564
TIBCO Hawk General
6.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO Operational Intelligence Hawk RedTail: versions 7.0.0 through 7.2.0.

CVE-2022-43096
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.

CVE-2022-29826
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.1%
2022 CWE-312 1 PoC

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.