3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-34758
Easergy P5 General
5.1
MEDIUM
EPSS
0.3%
2022 CWE-20 1 PoC

A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. Affected Products: Easergy P5 (V01.401.102 and prior)

CVE-2022-50684
Xperience General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.

CVE-2022-50941
BootCommerce General
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to session hijacking, phishing attacks, and application module manipulation.

CVE-2022-36872
Samsung Pay General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

CVE-2022-0870
gogs/gogs General ⚡ nuclei
5.0
MEDIUM
EPSS
9.1%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2022-3216
Game Boy Color General
5.0
MEDIUM
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability has been found in Nintendo Game Boy Color and classified as problematic. This vulnerability affects unknown code of the component Mobile Adapter GB. The manipulation leads to memory corruption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-208606 is the identifier assigned to this vulnerability.

CVE-2022-36871
Samsung Pay General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

CVE-2022-22265
🔥 KEV Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.2%
2022 CWE-703 1 PoC

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

CVE-2022-28197
Jetson AGX Xavier series, Jetson Xavier NX General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted data may allow a highly privileged local attacker to cause an integer overflow. This difficult-to-exploit vulnerability may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

CVE-2022-28780
Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

CVE-2022-43665
Alyac General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-823 1 PoC

A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-crafted PE file can lead to killing target process. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-4613
Passwordstate General
5.0
MEDIUM
EPSS
0.3%
2022 CWE-266 2 PoCs

A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216275.

CVE-2022-36870
Samsung Pay General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

CVE-2022-21147
Alyac General
5.0
MEDIUM
EPSS
0.2%
2022 CWE-823 1 PoC

An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-crafted PE file can trigger this vulnerability to cause denial of service and termination of malware scan. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-3705
vim General
5.0
MEDIUM
EPSS
0.5%
2022 CWE-119 1 PoC

A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324.

CVE-2022-31007
elabftw General
4.9
MEDIUM
EPSS
13.1%
2022 CWE-842 2 PoCs

eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the applica

CVE-2022-45326
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2022 1 PoC

An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.

CVE-2022-25786
GateManager General
4.9
MEDIUM
EPSS
0.3%
2022 CWE-420 1 PoC

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.

CVE-2022-26067
OAS Platform General
4.9
MEDIUM
EPSS
0.2%
2022 CWE-306 1 PoC

An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to arbitrary file read. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-39847
Samsung Mobile Devices General
4.9
MEDIUM
EPSS
0.0%
2022 CWE-416 1 PoC

Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.