7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-26068
pistacheio/pistache General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.

CVE-2022-4296
TL-WR740N General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-404 1 PoC

A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214812.

CVE-2022-21252
WebLogic Server Web Database
6.5
MEDIUM
EPSS
1.0%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity im

CVE-2022-4161
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-0001
Intel(R) Processors General
6.5
MEDIUM
EPSS
0.3%
2022 4 PoCs

Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2022-24189
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all requests to succeed, bypassing authorization and session management. The impact of this vulnerability allows an attacker POST api calls with other users unique identifiers and enumerate information of all other end-users.

CVE-2022-4239
Workreap Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

CVE-2022-4266
Bulk Delete Users by Email Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attack

CVE-2022-50979
VibroLine VLX1 HD 5.0 General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

CVE-2022-1223
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-4107
SMSA Shipping for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

CVE-2022-42197
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

CVE-2022-38970
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.

CVE-2022-4384
Stream Web Windows
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.

CVE-2022-27630
LinkHub Mesh Wifi General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVE-2022-21569
MySQL Server Database
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-0678
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-21561
JD Edwards EnterpriseOne Tools Web Database
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-45962
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.

CVE-2022-38750
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.