7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24729
ckeditor4 General
6.5
MEDIUM
EPSS
0.8%
2022 CWE-400 2 PoCs

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVE-2022-4868
froxlor/froxlor General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVE-2022-21576
FLEXCUBE Universal Banking Web Database
6.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUB

CVE-2022-34387
SupportAssist General
6.4
MEDIUM
EPSS
0.1%
2022 CWE-377 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.

CVE-2022-2326
GitLab DevOps
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVE-2022-32506
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-23432
Samsung Mobile Devices with Exynos chipsets General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

CVE-2022-41545
Software Genérico Web Networking
6.4
MEDIUM
EPSS
0.0%
2022 1 PoC

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.

CVE-2022-2965
notrinos/notrinoserp General
6.4
MEDIUM
EPSS
0.3%
2022 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.

CVE-2022-33928
Wyse Management Suite General
6.4
MEDIUM
EPSS
0.1%
2022 CWE-256 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

CVE-2022-21584
Banking Trade Finance Web Database
6.4
MEDIUM
EPSS
1.5%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-4470
Widgets for Google Reviews Web Windows
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3269
ikus060/rdiffweb General
6.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

CVE-2022-23540
node-jsonwebtoken General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the `jwt.verify()` function. This issue has been fixed, please update to version 9.0.0 which removes the default support for the none algorithm in the `jwt.verify()` method. There will be no impact, if you update to version 9.0.0 and you don’t need to allow for the `none` algorithm. If you need 'none' algorithm, you have to

CVE-2022-0966
star7th/showdoc Web
6.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.

CVE-2022-40635
Crafter CMS Web
6.4
MEDIUM
EPSS
13.0%
2022 CWE-913 1 PoC

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.

CVE-2022-39854
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

CVE-2022-21583
Banking Trade Finance Web Database
6.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data and unaut

CVE-2022-21381
Enterprise Session Border Controller Web Database
6.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. While the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Con

CVE-2022-4503
openemr/openemr Web
6.4
MEDIUM
EPSS
0.8%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.