9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-30755
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

CVE-2022-3423
nocodb/nocodb General
7.3
HIGH
EPSS
1.1%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

CVE-2022-32543
Alyac General
7.3
HIGH
EPSS
0.2%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2652
umlaeute/v4l2loopback General
7.3
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row).

CVE-2022-36833
Game Optimizing Service General
7.3
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.

CVE-2022-39858
FactoryCamera General
7.3
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.

CVE-2022-28194
Jetson AGX Xavier series, Jetson Xavier NX General
7.3
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-1061
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-122 1 PoC

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

CVE-2022-22521
Benchmark Programming Tool General
7.3
HIGH
EPSS
0.1%
2022 CWE-732 2 PoCs

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

CVE-2022-0272
detekt/detekt General
7.3
HIGH
EPSS
0.3%
2022 CWE-611 1 PoC

Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.

CVE-2022-3664
Bento4 General
7.3
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

CVE-2022-26671
Personnel Attendance Management system General
7.3
HIGH
EPSS
0.6%
2022 CWE-798 1 PoC

Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

CVE-2022-36069
poetry General
7.3
HIGH
EPSS
0.7%
2022 CWE-94 1 PoC

Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repository URL). When building the commands, Poetry correctly avoids Command Injection vulnerabilities by passing an array of arguments instead of a command string. However, there is the possibility that a user input starts with a dash (`-`) and is therefore treated as an optional argument instead of a positional one. This can lead to Code Execution because some o

CVE-2022-0777
microweber/microweber General
7.3
HIGH
EPSS
0.5%
2022 CWE-640 1 PoC

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0839
liquibase/liquibase General
7.3
HIGH
EPSS
0.2%
2022 CWE-611 3 PoCs

Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

CVE-2022-1795
gpac/gpac General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-1073
Automatic Question Paper Generator General
7.3
HIGH
EPSS
0.3%
2022 CWE-640 1 PoC

A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

CVE-2022-29886
Alyac General
7.3
HIGH
EPSS
0.1%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-4141
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVE-2022-0476
radareorg/radare2 General
7.3
HIGH
EPSS
0.2%
2022 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.