7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25869
angular Web
4.2
MEDIUM
EPSS
5.8%
2022 CWE-79 12 PoCs

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

CVE-2022-25778
GateManager Web
4.2
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

CVE-2022-21555
MySQL Server Database
4.2
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the MySQL Shell for VS Code product of Oracle MySQL (component: Shell: GUI). Supported versions that are affected are 1.1.8 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Shell for VS Code executes to compromise MySQL Shell for VS Code. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Shell for VS Code, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauth

CVE-2022-24927
Samsung Video Player General
4.2
MEDIUM
EPSS
0.1%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.

CVE-2022-21439
Solaris Operating System Database
4.2
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.2 (Availability impacts). CVSS Vector: (CVSS

CVE-2022-25781
GateManager Web
4.2
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.

CVE-2022-25820
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2022 CWE-307 1 PoC

A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

CVE-2022-24932
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2022 CWE-424 1 PoC

Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.

CVE-2022-2870
laravel Web
4.1
MEDIUM
EPSS
0.4%
2022 CWE-502 1 PoC

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

CVE-2022-24929
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-926 1 PoC

Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

CVE-2022-21611
MySQL Server Database
4.1
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.30 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-25816
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

CVE-2022-29839
My Cloud Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2022-30740
Samsung Internet General
4.1
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

CVE-2022-0414
dolibarr/dolibarr General
4.1
MEDIUM
EPSS
0.3%
2022 CWE-1284 1 PoC

Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.

CVE-2022-32491
CPG BIOS General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-119 1 PoC

Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.

CVE-2022-28192
NVIDIA Virtual GPU Software and NVIDIA Cloud Gaming Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

CVE-2022-33692
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

CVE-2022-39878
Samsung Checkout General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit intent broadcast.

CVE-2022-25822
Samsung Mobile devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-362 1 PoC

An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.