7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2130
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
46.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2022-46698
iCloud for Windows Cloud Windows
6.5
MEDIUM
EPSS
0.7%
2022 5 PoCs

A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.

CVE-2022-0579
snipe/snipe-it General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

CVE-2022-2188
DXL Broker General
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.

CVE-2022-3869
froxlor/froxlor General ⚡ nuclei
6.5
MEDIUM
EPSS
14.9%
2022 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

CVE-2022-3882
Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-35054
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.

CVE-2022-25818
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

CVE-2022-23061
Shopizer General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-639 1 PoC

In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.

CVE-2022-21454
MySQL Server Database
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-4548
Optimize images ALT Text (alt tag) & names for SEO using AI Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-3781
Remote Desktop Manager General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-311 1 PoC

Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.

CVE-2022-45895
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

CVE-2022-35028
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.

CVE-2022-34366
SupportAssist Client Consumer General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-942 1 PoC

Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

CVE-2022-40982
Intel(R) Processors General
6.5
MEDIUM
EPSS
0.7%
2022 1 PoC

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-4150
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.9%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-1185
GitLab DevOps
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVE-2022-1287
School Club Application System Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-99 1 PoC

A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalation. The attack can be initiated remotely and does not require authentication. The exploit has been disclosed to the public and may be used.

CVE-2022-20816
Cisco Unified Communications Manager Web Networking
6.5
MEDIUM
EPSS
0.7%
2022 CWE-22 1 PoC

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an affected system. This vulnerability exists because the affected software does not properly validate HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system.