3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-25858
terser General
5.3
MEDIUM
EPSS
3.6%
2022 2 PoCs

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

CVE-2022-24373
react-native-reanimated General
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.

CVE-2022-37313
Software Genérico General
5.3
MEDIUM
EPSS
0.5%
2022 1 PoC

OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

CVE-2022-3668
Bento4 General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-404 1 PoC

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

CVE-2022-4366
lirantal/daloradius General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.

CVE-2022-26090
SamsungContacts General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-815 1 PoC

Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.

CVE-2022-38956
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to replace the user-uploaded firmware image with an original old firmware image. This affects Firmware 1.1.1_1.1.9 and earlier.

CVE-2022-23002
Sweet B Library General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-703 1 PoC

When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output will cause an error when used in other operations. This may be leveraged by an attacker to cause an error scenario in applications which use the library, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components.

CVE-2022-30736
Samsung Account General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

CVE-2022-21195
url-regex General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash.

CVE-2022-46354
SCALANCE X204RNA (HSR) General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances.

CVE-2022-22289
S Assistant General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

CVE-2022-33715
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.

CVE-2022-35284
Security Verify Information Queue General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 230811.

CVE-2022-25918
shescape General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.

CVE-2022-3065
jgraph/drawio General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.

CVE-2022-30076
Software Genérico General
5.3
MEDIUM
EPSS
12.4%
2022 1 PoC

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

CVE-2022-31711
vRealize Log Insight (vRLI) General ⚡ nuclei
5.3
MEDIUM
EPSS
81.7%
2022 1 PoC

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.

CVE-2022-41988
OpenImageIO General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.