3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-1383
radareorg/radare2 General
4.8
MEDIUM
EPSS
0.2%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

CVE-2022-29475
iota All-In-One Security Kit General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-294 1 PoC

An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2022-4402
DocSys General
4.7
MEDIUM
EPSS
0.8%
2022 CWE-22 1 PoC

A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.

CVE-2022-29800
networkd-dispatcher General
4.7
MEDIUM
EPSS
0.1%
2022 CWE-367 1 PoC

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVE-2022-0692
rudloff/alltube General ⚡ nuclei
4.7
MEDIUM
EPSS
20.8%
2022 CWE-601 1 PoC

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

CVE-2022-0239
stanfordnlp/corenlp General
4.7
MEDIUM
EPSS
0.0%
2022 CWE-611 1 PoC

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2022-3549
Simple Cold Storage Management System General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-266 1 PoC

A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211049 was assigned to this vulnerability.

CVE-2022-1384
Mattermost General
4.7
MEDIUM
EPSS
0.3%
2022 CWE-477 1 PoC

Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.

CVE-2022-31238
PowerScale OneFS General
4.7
MEDIUM
EPSS
0.1%
2022 1 PoC

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this vulnerability, leading to information disclosure.

CVE-2022-41215
SAP NetWeaver ABAP Server and ABAP Platform General
4.7
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.

CVE-2022-49633
Linux General
4.7
MEDIUM
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: icmp: Fix data-races around sysctl_icmp_echo_enable_probe. While reading sysctl_icmp_echo_enable_probe, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

CVE-2022-4732
microweber/microweber General
4.7
MEDIUM
EPSS
1.1%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-3303
Linux kernel General
4.7
MEDIUM
EPSS
0.0%
2022 CWE-667 1 PoC

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition

CVE-2022-30730
Samsung Pass General
4.6
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.

CVE-2022-39900
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.

CVE-2022-28782
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2022 CWE-424 1 PoC

Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.

CVE-2022-30574
TIBCO FTL - Community Edition General
4.6
MEDIUM
EPSS
0.0%
2022 1 PoC

The ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, TIBCO eFTL - Enterprise Edition, and TIBCO eFTL - Enterprise Edition contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to obtain user credentials to the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.0.0 through 6.8.0, TIBCO FTL - Developer Edition: ver

CVE-2022-1893
polonel/trudesk General
4.6
MEDIUM
EPSS
0.3%
2022 CWE-212 1 PoC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-2997
snipe/snipe-it General
4.6
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.

CVE-2022-28196
Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 NX, Jetson TX2 series General
4.6
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.