3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2309
lxml/lxml General
5.3
MEDIUM
EPSS
0.9%
2022 CWE-476 1 PoC

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that se

CVE-2022-44005
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.

CVE-2022-25758
scss-tokenizer General
5.3
MEDIUM
EPSS
0.5%
2022 2 PoCs

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVE-2022-44381
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

CVE-2022-0574
publify/publify General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

CVE-2022-0713
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-3272
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-130 1 PoC

Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-3175
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-756 1 PoC

Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.

CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

CVE-2022-22496
Spectrum Protect Server General
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.

CVE-2022-47547
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbehaves by never forwarding topic messages.

CVE-2022-42127
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.

CVE-2022-36354
OpenImageIO General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-193 1 PoC

A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-45354
Download Monitor General ⚡ nuclei
5.3
MEDIUM
EPSS
87.6%
2022 CWE-200 2 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

CVE-2022-22409
Aspera Faspex General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.

CVE-2022-36781
ScreenConnect General
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.

CVE-2022-1437
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

CVE-2022-2930
octoprint/octoprint General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-30743
Samsung Account General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

CVE-2022-35715
InfoSphere Information Server General
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.