9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-21803
nconf General
7.3
HIGH
EPSS
0.9%
2022 2 PoCs

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

CVE-2022-1785
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

CVE-2022-21189
dexie General
7.3
HIGH
EPSS
0.2%
2022 2 PoCs

The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the Dexie.setByKeyPath(obj, keyPath, value) function which does not properly check the keys being set (like __proto__ or constructor). This can allow an attacker to add/modify properties of the Object.prototype leading to prototype pollution vulnerability. **Note:** This vulnerability can occur in multiple ways, for example when modifying a collection with untrusted user input.

CVE-2022-3666
Bento4 General
7.3
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212006 is the identifier assigned to this vulnerability.

CVE-2022-0083
livehelperchat/livehelperchat General
7.3
HIGH
EPSS
0.2%
2022 CWE-209 1 PoC

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

CVE-2022-0849
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-39857
FactoryCameraFB General
7.3
HIGH
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.

CVE-2022-1160
vim/vim General
7.3
HIGH
EPSS
0.6%
2022 CWE-122 1 PoC

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

CVE-2022-0265
hazelcast/hazelcast General
7.3
HIGH
EPSS
8.3%
2022 CWE-611 2 PoCs

Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

CVE-2022-45101
PowerScale OneFS General
7.3
HIGH
EPSS
4.2%
2022 CWE-274 1 PoC

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution.

CVE-2022-46370
FTP server General
7.3
HIGH
EPSS
0.1%
2022 1 PoC

Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification.

CVE-2022-37331
Open Babel General
7.3
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2580
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.

CVE-2022-1621
vim/vim General
7.3
HIGH
EPSS
0.1%
2022 CWE-122 2 PoCs

Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CVE-2022-2927
notrinos/notrinoserp General
7.3
HIGH
EPSS
0.4%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.

CVE-2022-4173
Avast and AVG Antivirus General
7.3
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.

CVE-2022-1616
vim/vim General
7.3
HIGH
EPSS
0.2%
2022 CWE-416 2 PoCs

Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CVE-2022-1052
radareorg/radare2 General
7.3
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-26310
Pandora FMS General
7.3
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation to access the privileges of a higher-level user or typically an admin user.