7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4024
Registration Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVE-2022-35064
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adcdb in __asan_memset.

CVE-2022-45170
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.

CVE-2022-22760
Firefox Web
6.5
MEDIUM
EPSS
0.2%
2022 2 PoCs

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-35034
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.

CVE-2022-3879
Car Dealer (Dealership) and Vehicle sales WordPress Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-35039
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.

CVE-2022-40845
Software Genérico Networking
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.

CVE-2022-45130
Software Genérico Web
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.

CVE-2022-35044
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x617087.

CVE-2022-4850
usememos/memos Web
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-21565
Database - Enterprise Edition Database
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).

CVE-2022-35053
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.

CVE-2022-0374
livehelperchat/livehelperchat Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

CVE-2022-43022
Software Genérico Database
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVE-2022-35049
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b03b5.

CVE-2022-27633
LinkHub Mesh Wifi General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-200 1 PoC

An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVE-2022-28287
Firefox General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.

CVE-2022-4296
TL-WR740N General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-404 1 PoC

A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214812.

CVE-2022-35035
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.