7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2020
Prison Management System General
2.4
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=system_info of the component System Name Handler. The manipulation with the input <img src="" onerror="alert(1)"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-3992
Sanitization Management System General
2.4
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this vulnerability is an unknown functionality of the file admin/?page=system_info of the component Banner Image Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-213571.

CVE-2022-33720
Samsung Mobile Devices General
2.4
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.

CVE-2022-3519
Sanitization Management System General
2.4
LOW
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability classified as problematic was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Quote Requests Tab. The manipulation of the argument Manage Remarks leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-211015.

CVE-2022-1840
Home Clean Services Management System Web
2.4
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but demands authentication. Exploit details have been disclosed to the public.

CVE-2022-4233
Event Registration System General
2.4
LOW
EPSS
0.4%
2022 CWE-707 1 PoC

A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /event/admin/?page=user/list. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-214591.

CVE-2022-3547
Simple Cold Storage Management System General
2.4
LOW
EPSS
0.6%
2022 CWE-707 1 PoC

A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /csms/admin/?page=system_info of the component Setting Handler. The manipulation of the argument System Name/System Short Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-211047.

CVE-2022-32872
iOS General
2.4
LOW
EPSS
0.1%
2022 2 PoCs

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.

CVE-2022-4053
Student Attendance Management System Web
2.4
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.

CVE-2022-39906
Samsung Mobile Devices General
2.3
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.

CVE-2022-33716
Samsung Mobile Devices General
2.3
LOW
EPSS
0.0%
2022 CWE-457 1 PoC

An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.

CVE-2022-31628
PHP Web
2.3
LOW
EPSS
0.0%
2022 CWE-674 1 PoC

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVE-2022-33686
Samsung Mobile Devices General
2.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

CVE-2022-4614
alagrede/znote-app Web
2.3
LOW
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11.

CVE-2022-28794
Samsung Mobile Devices General
2.2
LOW
EPSS
0.0%
2022 CWE-213 1 PoC

Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

CVE-2022-29247
electron Web
2.2
LOW
EPSS
0.8%
2022 CWE-668 1 PoC

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with `nodeIntegrationInSubFrames` enabled which in turn allows effective access to `ipcRenderer`. The `nodeIntegrationInSubFrames` option does not implicitly grant Node.js access. Rather, it depends on the existing sandbox setting. If an application is sandboxed, then `nodeIntegrationInSubFrames` just gives access to the sandboxed

CVE-2022-24924
LiveWallpaper General
2.2
LOW
EPSS
2.9%
2022 CWE-284 2 PoCs

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

CVE-2022-33693
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

CVE-2022-25831
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.

CVE-2022-33699
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.