7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2473
WP-UserOnline Web Windows
5.5
MEDIUM
EPSS
1.0%
2022 CWE-79 3 PoCs

The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The only affects multi-site installations and installations where unfiltered_html is disabled.

CVE-2022-45586
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVE-2022-4285
binutils General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.

CVE-2022-3108
Kernel General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-252 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. kfd_parse_subtype_iolink in drivers/gpu/drm/amd/amdkfd/kfd_crat.c lacks check of the return value of kmemdup().

CVE-2022-34386
SupportAssist Client Consumer General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-321 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

CVE-2022-3690
Popup Maker Web Windows
5.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins

CVE-2022-28356
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2022 2 PoCs

In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.

CVE-2022-34710
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.7%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-39845
Samsung Kies General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-354 1 PoC

Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.

CVE-2022-28188
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.

CVE-2022-2708
Gym Management System Web Database
5.5
MEDIUM
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_login with the input 123@xx.com' OR (SELECT 9084 FROM(SELECT COUNT(*),CONCAT(0x7178767871,(SELECT (ELT(9084=9084,1))),0x71767a6271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- dPvW leads to sql injection. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-205833 was assigned to this vulnerability.

CVE-2022-41844
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.

CVE-2022-1622
libtiff General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

CVE-2022-39836
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.

CVE-2022-49326
Linux Web
5.5
MEDIUM
EPSS
0.0%
2022 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: rtl818x: Prevent using not initialized queues Using not existing queues can panic the kernel with rtl8180/rtl8185 cards. Ignore the skb priority for those cards, they only have one tx queue. Pierre Asselin (pa@panix.com) reported the kernel crash in the Gentoo forum: https://forums.gentoo.org/viewtopic-t-1147832-postdays-0-postorder-asc-start-25.html He also confirmed that this patch fixes the issue. In summary this happened: After updating wpa_supplicant from 2.9 to 2.10 the kernel crashed with a "divide error: 0000" whe

CVE-2022-30732
Samsung Account General
5.5
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.

CVE-2022-42851
tvOS General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.

CVE-2022-2057
libtiff General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

CVE-2022-42862
macOS General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.

CVE-2022-47929
Software Genérico Web
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This affects qdisc_graft in net/sched/sch_api.c.