7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2408
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVE-2022-1337
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.

CVE-2022-3514
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVE-2022-30543
InRouter302 Networking
4.3
MEDIUM
EPSS
0.6%
2022 CWE-489 1 PoC

A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-27841
Samsung Pass General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-703 1 PoC

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVE-2022-3173
snipe/snipe-it General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.

CVE-2022-4770
Pentaho Business Analytics Server Database
4.3
MEDIUM
EPSS
0.4%
2022 CWE-209 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). 

CVE-2022-3282
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

CVE-2022-2405
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

CVE-2022-21383
Enterprise Session Border Controller Web Database
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Session Border Controller. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/

CVE-2022-0869
nitely/spirit General ⚡ nuclei
4.3
MEDIUM
EPSS
7.4%
2022 CWE-601 1 PoC

Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.

CVE-2022-3223
jgraph/drawio Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.

CVE-2022-1174
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVE-2022-27172
InRouter302 Networking
4.3
MEDIUM
EPSS
0.4%
2022 CWE-259 1 PoC

A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-21393
Database - Enterprise Edition Database
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVE-2022-35507
Software Genérico Web ⚡ nuclei
4.3
MEDIUM
EPSS
14.3%
2022 1 PoC

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

CVE-2022-3585
Simple Cold Storage Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-863 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-211194 is the identifier assigned to this vulnerability.

CVE-2022-4246
PotPlayer General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214623.

CVE-2022-42129
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.

CVE-2022-3245
microweber/microweber Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-94 1 PoC

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.