7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4605
flatpressblog/flatpress Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2022-21621
VM VirtualBox Database
6.0
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Virtua

CVE-2022-22487
Spectrum Protect Server General
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.

CVE-2022-0419
radareorg/radare2 General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-28541
Samsung Update General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.

CVE-2022-24853
metabase Windows
5.9
MEDIUM
EPSS
9.7%
2022 CWE-200 1 PoC

Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our GeoJSON support. While we do validation to not return contents of arbitrary URLs, there is a case where a particularly crafted request could result in file access on windows, which allows enabling an `NTLM relay attack`, potentially allowing an attacker to receive the system password hash. If you use Windows and are on this version of Metabase, please upgrade immediately. The following patches (or greater versions) are available: 0.42.4 and 1.42.4

CVE-2022-36873
com.samsung.android.waterplugin General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.

CVE-2022-45480
PC Keyboard WiFi & Bluetooth General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-39861
FactoryCamera General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.

CVE-2022-25897
org.eclipse.milo:sdk-server General
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-36874
Waterplugin General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.

CVE-2022-36861
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

CVE-2022-22464
Security Verify Access General
5.9
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

CVE-2022-26099
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVE-2022-34716
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) General
5.9
MEDIUM
EPSS
1.0%
2022 1 PoC

.NET Spoofing Vulnerability

CVE-2022-45483
Lazy Mouse General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-21519
MySQL Cluster Database
5.9
MEDIUM
EPSS
1.0%
2022 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-40693
SDS-3008 Series Industrial Ethernet Switch General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-319 2 PoCs

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2022-3590
WordPress Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
90.8%
2022 4 PoCs

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVE-2022-42966
cleo General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method