7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25825
Samsung Account General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.

CVE-2022-43849
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a denial of service. IBM X-Force ID: 239170.

CVE-2022-36831
Samsung notes General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.

CVE-2022-42118
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
13.2%
2022 1 PoC

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.

CVE-2022-40712
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2022 1 PoC

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.

CVE-2022-21257
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to

CVE-2022-3578
ProfileGrid – User Profiles, Memberships, Groups and Communities Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
6.4%
2022 CWE-79 1 PoC

The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-4971
Social Sharing Plugin – Sassy Social Share Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 CWE-79 1 PoC

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2022-34474
Firefox General
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.

CVE-2022-0637
mozilla/pollbot General
6.1
MEDIUM
EPSS
0.2%
2022 2 PoCs

open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6

CVE-2022-31160
jquery-ui Web
6.1
MEDIUM
EPSS
7.8%
2022 CWE-79 2 PoCs

jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, s

CVE-2022-40879
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.4%
2022 0 PoCs

kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'

CVE-2022-0421
Five Star Restaurant Reservations Web Windows
6.1
MEDIUM
EPSS
1.0%
2022 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

CVE-2022-0891
libtiff General
6.1
MEDIUM
EPSS
0.0%
2022 2 PoCs

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVE-2022-42071
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.

CVE-2022-46073
Software Genérico DevOps Web ⚡ nuclei
6.1
MEDIUM
EPSS
29.5%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-44897
Software Genérico Web
6.1
MEDIUM
EPSS
1.5%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the show_number parameter.

CVE-2022-45098
PowerScale OneFS Cloud
6.1
MEDIUM
EPSS
0.0%
2022 CWE-532 1 PoC

Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.

CVE-2022-4310
Slimstat Analytics Web Windows
6.1
MEDIUM
EPSS
1.8%
2022 1 PoC

The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs