7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0090
GitLab DevOps
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVE-2022-39902
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

CVE-2022-3873
jgraph/drawio Web
6.5
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2.

CVE-2022-2401
Mattermost Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

CVE-2022-2188
DXL Broker General
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.

CVE-2022-35035
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.

CVE-2022-40982
Intel(R) Processors General
6.5
MEDIUM
EPSS
0.7%
2022 1 PoC

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-22748
Firefox ESR General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVE-2022-42282
NVIDIA DGX servers Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

CVE-2022-2402
ESET Endpoint Encryption General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-121 2 PoCs

The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

CVE-2022-3511
Awesome Support Web Windows
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

CVE-2022-33925
Wyse Management Suite General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.

CVE-2022-0950
star7th/showdoc General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-35040
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b5567.

CVE-2022-2130
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
46.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2022-40959
Firefox ESR General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVE-2022-0955
pimcore/data-hub Web
6.5
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.

CVE-2022-29888
InRouter302 Web Networking
6.5
MEDIUM
EPSS
1.5%
2022 CWE-489 1 PoC

A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-0514
crater-invoice/crater General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

CVE-2022-26135
Jira Core Server General
6.5
MEDIUM
EPSS
89.3%
2022 1 PoC

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.