7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4005
Donation Button Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-22109
DaybydayCRM Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim’s browser when they open the “/tasks” page to view all the tasks.

CVE-2022-25875
svelte Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

CVE-2022-0903
Mattermost General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.

CVE-2022-42892
syngo Dynamics General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-23 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder accessible to the account assigned to the website’s application pool.

CVE-2022-39862
Samsung Mobile Devices Web
5.3
MEDIUM
EPSS
0.3%
2022 CWE-285 1 PoC

Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.

CVE-2022-4646
ikus060/rdiffweb Web
5.3
MEDIUM
EPSS
0.0%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.

CVE-2022-0170
chocobozzz/peertube General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

peertube is vulnerable to Improper Access Control

CVE-2022-42254
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.3
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.

CVE-2022-23429
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.

CVE-2022-23513
AdminLTE Web
5.3
MEDIUM
EPSS
9.2%
2022 CWE-284 1 PoC

Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.

CVE-2022-25819
Samsung Mobile Devices with Exynos chipsets General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.

CVE-2022-33932
PowerScale OneFS General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-419 1 PoC

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotected primary channel vulnerability. An unauthenticated network malicious attacker may potentially exploit this vulnerability, leading to a denial of filesystem services.

CVE-2022-24723
URI.js Web
5.3
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

CVE-2022-37774
Software Genérico Web
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

CVE-2022-1563
wp-graphql-woocommerce Web Windows
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

CVE-2022-36781
ScreenConnect General
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.

CVE-2022-21341
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM

CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.