7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22323
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 218379.

CVE-2022-0407
vim/vim General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-22312
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

CVE-2022-0231
livehelperchat/livehelperchat Web
5.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-2355
Easy Username Updater Web Windows
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin

CVE-2022-21609
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessi

CVE-2022-22284
Samsung Internet General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

CVE-2022-30625
Chcnav - P5E GNSS General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-548 1 PoC

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

CVE-2022-24926
SmartTagPlugin Web
5.7
MEDIUM
EPSS
0.4%
2022 CWE-20 1 PoC

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

CVE-2022-0505
microweber/microweber Web
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-4694
usememos/memos Web
5.7
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-39899
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

CVE-2022-2549
gpac/gpac General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-3881
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log Web Windows
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-1648
Pandora FMS Web
5.7
MEDIUM
EPSS
2.8%
2022 CWE-23 1 PoC

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.

CVE-2022-21557
WebLogic Server DevOps Database
5.7
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete acc

CVE-2022-38124
SiteManager General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-267 1 PoC

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

CVE-2022-3290
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-130 1 PoC

Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-0245
livehelperchat/livehelperchat Web
5.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.

CVE-2022-3516
librenms/librenms Web
5.7
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.