7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3258
Workforce Access Windows
3.7
LOW
EPSS
0.2%
2022 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.

CVE-2022-42965
snowflake-connector-python General
3.7
LOW
EPSS
0.2%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method

CVE-2022-21443
Java SE JDK and JRE Database
3.7
LOW
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Or

CVE-2022-21619
Java SE JDK and JRE Database
3.7
LOW
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM

CVE-2022-1907
bfabiszewski/libmobi General
3.6
LOW
EPSS
0.1%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

CVE-2022-39863
Samsung Account General
3.6
LOW
EPSS
0.2%
2022 CWE-20 1 PoC

Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.

CVE-2022-3273
ikus060/rdiffweb General
3.6
LOW
EPSS
0.2%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

CVE-2022-39892
Samsung Pass General
3.6
LOW
EPSS
0.2%
2022 CWE-287 1 PoC

Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.

CVE-2022-1908
bfabiszewski/libmobi General
3.6
LOW
EPSS
0.2%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

CVE-2022-0861
McAfee ePolicy Orchestrator (ePO) General
3.5
LOW
EPSS
0.2%
2022 CWE-611 1 PoC

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.

CVE-2022-0489
GitLab DevOps
3.5
LOW
EPSS
0.2%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVE-2022-0088
yourls/yourls Web
3.5
LOW
EPSS
0.6%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.

CVE-2022-2032
Pandora FMS General
3.5
LOW
EPSS
0.6%
2022 CWE-79 1 PoC

In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

CVE-2022-1503
CMS Web
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> leads to cross site scripting. The attack may be launched remotely but requires authentication. Expoit details have been disclosed within the advisory.

CVE-2022-1075
College Website Management System Web
3.5
LOW
EPSS
0.2%
2022 CWE-79 2 PoCs

A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication.

CVE-2022-1817
Badminton Center Management System Web
3.5
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

CVE-2022-3452
Book Store Management System Web
3.5
LOW
EPSS
0.2%
2022 CWE-707 2 PoCs

A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210436.

CVE-2022-4891
Sisimai General
3.5
LOW
EPSS
0.3%
2022 CWE-1333 1 PoC

A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the function to_plain of the file lib/sisimai/string.rb. The manipulation leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. Upgrading to version 4.25.14p12 is able to address this issue. The name of the patch is 51fe2e6521c9c02b421b383943dc9e4bbbe65d4e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218452.

CVE-2022-2690
Wedding Hall Booking System General
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vulnerability is an unknown functionality of the file /whbs/?page=my_bookings of the component Booking Form. The manipulation of the argument Remarks leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205813 was assigned to this vulnerability.

CVE-2022-4279
Human Resource Management System Web
3.5
LOW
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Human Resource Management System 1.0. Affected is an unknown function of the file /hrm/employeeview.php. The manipulation of the argument search leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214776.