3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0560
microweber/microweber General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-601 1 PoC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-1982
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

CVE-2022-3816
Bento4 General
4.3
MEDIUM
EPSS
0.5%
2022 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.

CVE-2022-30738
Samsung Internet General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-703 1 PoC

Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.

CVE-2022-27841
Samsung Pass General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-703 1 PoC

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVE-2022-24403
TETRA Standard General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-327 1 PoC

The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known encrypted/unencrypted identity pairs.

CVE-2022-42126
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

CVE-2022-32169
bytebase General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

CVE-2022-0869
nitely/spirit General ⚡ nuclei
4.3
MEDIUM
EPSS
7.4%
2022 CWE-601 1 PoC

Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.

CVE-2022-22107
DaybydayCRM General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.

CVE-2022-42159
Software Genérico General
4.3
MEDIUM
EPSS
0.5%
2022 1 PoC

D-Link COVR 1200,1202,1203 v1.08 was discovered to have a predictable seed in a Pseudo-Random Number Generator.

CVE-2022-3814
Bento4 General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212680.

CVE-2022-1328
Mutt General
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line

CVE-2022-41273
Sourcing and SAP Contract Lifecycle Management General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-601 1 PoC

Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the victim doesn’t suspect the threat, they click on the link, log in to SAP Sourcing and CLM and at this point, they get redirected to a malicious website.            

CVE-2022-4612
Passwordstate General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-522 2 PoCs

A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerability affects unknown code. The manipulation leads to insufficiently protected credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. VDB-216274 is the identifier assigned to this vulnerability.

CVE-2022-1210
LibTIFF General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-400 2 PoCs

A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.

CVE-2022-4808
usememos/memos General
4.2
MEDIUM
EPSS
0.2%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-25820
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2022 CWE-307 1 PoC

A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

CVE-2022-24927
Samsung Video Player General
4.2
MEDIUM
EPSS
0.1%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.

CVE-2022-24932
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2022 CWE-424 1 PoC

Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.