7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-44870
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 2 PoCs

A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

CVE-2022-40912
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

CVE-2022-43017
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-31456
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name parameter.

CVE-2022-22555
PowerStore General
6.0
MEDIUM
EPSS
0.6%
2022 CWE-78 2 PoCs

Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.

CVE-2022-31596
SAP Business Objects Platform (Monitoring DB) Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-668 1 PoC

Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal) system data which would otherwise be restricted. Also, a potential attack could be used to leave the CMS's scope and impact the database. A successful attack could have a low impact on confidentiality, a high impact on integrity, and a low impact on availability.

CVE-2022-26579
Software Genérico General
6.0
MEDIUM
EPSS
0.0%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages. The attacker must have shell access to the device and gain root privileges in order to exploit this vulnerability.

CVE-2022-32493
CPG BIOS General
6.0
MEDIUM
EPSS
0.0%
2022 CWE-121 1 PoC

Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-34709
Windows 10 Version 1809 Windows
6.0
MEDIUM
EPSS
1.3%
2022 1 PoC

Windows Defender Credential Guard Security Feature Bypass Vulnerability

CVE-2022-0915
Sync Windows
6.0
MEDIUM
EPSS
0.0%
2022 CWE-367 1 PoC

There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.

CVE-2022-39423
VM VirtualBox Database
6.0
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. C

CVE-2022-42285
NVIDIA DGX servers General
6.0
MEDIUM
EPSS
0.0%
2022 CWE-1231 1 PoC

DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, escalation of privileges, or data tampering.

CVE-2022-48682
Software Genérico General
6.0
MEDIUM
EPSS
0.0%
2022 1 PoC

In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.

CVE-2022-34449
PowerPath Management Appliance General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-798 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application.

CVE-2022-41261
Solution Manager (Diagnostic Agent) Windows
6.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation can make the attacker access files and systems for which he/she is not authorized.

CVE-2022-42286
NVIDIA DGX servers General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-119 1 PoC

DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.

CVE-2022-4314
ikus060/rdiffweb General
6.0
MEDIUM
EPSS
0.4%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.

CVE-2022-42287
NVIDIA DGX servers General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.

CVE-2022-4605
flatpressblog/flatpress Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.