7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1002
Mattermost General
2.0
LOW
EPSS
0.2%
2022 CWE-80 1 PoC

Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.

CVE-2022-33699
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVE-2022-36857
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.

CVE-2022-30714
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-213 1 PoC

Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVE-2022-23830
3rd Gen AMD EPYC™ Processors General
1.9
LOW
EPSS
0.1%
2022 2 PoCs

SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.

CVE-2022-25828
Watch Active PlugIn General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-4610
Passwordstate General
1.9
LOW
EPSS
0.1%
2022 CWE-310 1 PoC

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptographic algorithm. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216272.

CVE-2022-25829
Watch Active2 PlugIn General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-36852
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

CVE-2022-25830
Galaxy Watch3 Plugin General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-29836
My Cloud Home Web Cloud
1.9
LOW
EPSS
0.2%
2022 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could also allow the attacker to initiate the installation of custom packages at these locations. This can only be exploited once the attacker has been authenticated to the device. This issue affects: Western Digital My Cloud Home and My Cloud Home Duo versions prior to 8.11.0-113 on Lin

CVE-2022-25823
Galaxy Watch Plugin General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.

CVE-2022-36330
My Cloud Home and My Cloud Home Duo Cloud
1.9
LOW
EPSS
0.4%
2022 CWE-120 1 PoC

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 

CVE-2022-30728
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-213 1 PoC

Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVE-2022-25827
Galaxy Watch PlugIn General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-25826
Galaxy S3 PlugIn Cloud
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-36876
Samsung Pass General
1.8
LOW
EPSS
0.1%
2022 CWE-285 1 PoC

Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.

CVE-2022-35411
Software Genérico Web
N/A
UNKNOWN
EPSS
71.3%
2022 3 PoCs

rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

CVE-2022-1593
Site Offline or Coming Soon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attack

CVE-2022-33996
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.