7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30731
My Files General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.

CVE-2022-29840
My Cloud OS 5 Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud OS 5 devices before 5.26.202.

CVE-2022-50683
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute in users' browsers through unvalidated form configuration settings.

CVE-2022-39855
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

CVE-2022-1934
mruby/mruby General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-50685
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVE-2022-4979
Experience Platform Web Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.

CVE-2022-50891
Owlfiles File Manager Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScript in users' browsers.

CVE-2022-28775
Samsung Flow General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.

CVE-2022-36848
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

CVE-2022-50681
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers.

CVE-2022-50804
JF511-TV Web Networking
5.1
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.

CVE-2022-50802
ETAP Safety Manager Web
5.1
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials or performing unauthorized actions.

CVE-2022-45478
Telepad General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-50951
WiFi File Transfer Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through file and folder names. Attackers can exploit the web server's input validation weakness to execute arbitrary JavaScript when users preview infected file paths, potentially compromising user browser sessions.

CVE-2022-4647
microweber/microweber Web
5.1
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-50941
BootCommerce General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to session hijacking, phishing attacks, and application module manipulation.

CVE-2022-50896
Testa Web
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.

CVE-2022-33731
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

CVE-2022-50940
Knap Advanced PHP Login Web
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script code in the name parameter. Attackers can exploit the vulnerability to execute arbitrary scripts in users and activity log backend modules, potentially leading to session hijacking and persistent phishing attacks.