7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4111
tooljet/tooljet General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-1284 1 PoC

Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.

CVE-2022-35066
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

CVE-2022-42197
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

CVE-2022-38750
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-28749
On-Premise Meeting Connectors General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of the host.

CVE-2022-22757
Firefox General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.

CVE-2022-21561
JD Edwards EnterpriseOne Tools Web Database
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-2730
openemr/openemr General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-21394
VM VirtualBox Database
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.32. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Sc

CVE-2022-22754
Firefox General
6.5
MEDIUM
EPSS
0.0%
2022 2 PoCs

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-34662
Apache DolphinScheduler Web
6.5
MEDIUM
EPSS
1.0%
2022 CWE-22 1 PoC

When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher

CVE-2022-4240
OneWireless General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 1 PoC

Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1

CVE-2022-35045
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0d63.

CVE-2022-4011
Simple History Plugin General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-707 1 PoC

A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213785 was assigned to this vulnerability.

CVE-2022-38751
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-4016
Booster for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks

CVE-2022-29914
Thunderbird General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVE-2022-0524
publify/publify General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

CVE-2022-3232
ikus060/rdiffweb Web
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.

CVE-2022-26023
InRouter302 Networking
6.5
MEDIUM
EPSS
0.3%
2022 CWE-489 1 PoC

A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this vulnerability.