3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-25901
cookiejar General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-1333 2 PoCs

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.

CVE-2022-21195
url-regex General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash.

CVE-2022-33715
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.

CVE-2022-35284
Security Verify Information Queue General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 230811.

CVE-2022-3065
jgraph/drawio General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.

CVE-2022-46354
SCALANCE X204RNA (HSR) General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances.

CVE-2022-31711
vRealize Log Insight (vRLI) General ⚡ nuclei
5.3
MEDIUM
EPSS
81.7%
2022 1 PoC

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.

CVE-2022-25918
shescape General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.

CVE-2022-1382
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.

CVE-2022-22289
S Assistant General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

CVE-2022-0903
Mattermost General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.

CVE-2022-30076
Software Genérico General
5.3
MEDIUM
EPSS
12.4%
2022 1 PoC

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

CVE-2022-3068
octoprint/octoprint General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-39275
saleor General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-863 1 PoC

Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose the following information: Estimating database row counts from tables with a sequential primary key or Exposing staff user and customer email addresses and full name through the `assignNavigation()` mutation. This issue has been patched in main and backported to multiple releases (3.7.17, 3.6.18, 3.5.23, 3.4.24, 3.3.26,

CVE-2022-23004
Sweet B Library General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-707 1 PoC

When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may be leveraged by an attacker to cause an error scenario, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components.

CVE-2022-3298
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-25883
semver General
5.3
MEDIUM
EPSS
0.6%
2022 CWE-1333 1 PoC

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

CVE-2022-2585
linux General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-416 4 PoCs

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

CVE-2022-0079
star7th/showdoc General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-209 1 PoC

showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

CVE-2022-32943
macOS General
5.3
MEDIUM
EPSS
0.5%
2022 2 PoCs

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.