3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-1815
jgraph/drawio General ⚡ nuclei
5.3
MEDIUM
EPSS
24.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

CVE-2022-32741
OTRS General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

CVE-2022-3364
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

CVE-2022-39881
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.6%
2022 CWE-20 1 PoC

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.

CVE-2022-42265
NVIDIA GPU Display Driver for Linux General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering.

CVE-2022-0578
publify/publify General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-94 1 PoC

Code Injection in GitHub repository publify/publify prior to 9.2.8.

CVE-2022-23429
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.

CVE-2022-41988
OpenImageIO General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-39262
glpi General
5.2
MEDIUM
EPSS
0.3%
2022 CWE-83 1 PoC

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrator can define rich-text content to be displayed on login page. The displayed content is can contains malicious code that can be used to steal credentials. This issue has been patched, please upgrade to version 10.0.4.

CVE-2022-26581
Software Genérico General
5.2
MEDIUM
EPSS
0.1%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2022-33695
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-732 1 PoC

Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

CVE-2022-39855
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

CVE-2022-30731
My Files General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.

CVE-2022-36848
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

CVE-2022-28775
Samsung Flow General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.

CVE-2022-45478
Telepad General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-1934
mruby/mruby General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-33731
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

CVE-2022-39875
Samsung Account General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.