3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-1754
polonel/trudesk General
8.4
HIGH
EPSS
0.5%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-22077
Snapdragon Mobile General
8.4
HIGH
EPSS
0.1%
2022 1 PoC

Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile

CVE-2022-27836
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.

CVE-2022-1803
polonel/trudesk General
8.4
HIGH
EPSS
0.3%
2022 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-0525
mruby/mruby General
8.4
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-4809
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4689
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-1813
yogeshojha/rengine General
8.3
HIGH
EPSS
11.4%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.

CVE-2022-1471
SnakeYAML General
8.3
HIGH
EPSS
93.8%
2022 CWE-20 2 PoCs

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVE-2022-4811
usememos/memos General
8.3
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

CVE-2022-4847
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-941 1 PoC

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1285
gogs/gogs General
8.3
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

CVE-2022-2732
openemr/openemr General
8.3
HIGH
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-1727
jgraph/drawio General
8.3
HIGH
EPSS
1.1%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.

CVE-2022-48474
Control de Ciber General
8.2
HIGH
EPSS
1.7%
2022 CWE-400 1 PoC

Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process.

CVE-2022-4801
usememos/memos General
8.2
HIGH
EPSS
0.2%
2022 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4806
usememos/memos General
8.2
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-0860
cobbler/cobbler General
8.2
HIGH
EPSS
0.7%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

CVE-2022-38491
Software Genérico General
8.2
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.