3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-25647
com.google.code.gson:gson General
7.7
HIGH
EPSS
2.8%
2022 1 PoC

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVE-2022-2003
DirectLOGIC D0-06 series CPUs General
7.7
HIGH
EPSS
0.1%
2022 CWE-319 1 PoC

AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions pr

CVE-2022-1071
mruby/mruby General
7.7
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-22988
EdgeRover General
7.7
HIGH
EPSS
0.1%
2022 CWE-275 1 PoC

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated access to the device.

CVE-2022-22264
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.

CVE-2022-3570
libtiff General
7.7
HIGH
EPSS
0.0%
2022 2 PoCs

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVE-2022-50976
VibroLine Configurator 5.0 General
7.7
HIGH
EPSS
0.0%
2022 CWE-1288 2 PoCs

A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.

CVE-2022-0895
microweber/microweber General
7.7
HIGH
EPSS
1.2%
2022 CWE-96 1 PoC

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-48685
Software Genérico General
7.7
HIGH
EPSS
0.0%
2022 1 PoC

An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.

CVE-2022-28781
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

CVE-2022-0908
libtiff General
7.7
HIGH
EPSS
0.0%
2022 1 PoC

Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.

CVE-2022-25898
jsrsasign General
7.7
HIGH
EPSS
1.8%
2022 4 PoCs

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.

CVE-2022-37317
Software Genérico General
7.6
HIGH
EPSS
0.2%
2022 1 PoC

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2022-27835
Samsung Mobile Devices General
7.6
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVE-2022-1926
polonel/trudesk General
7.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-2862
vim/vim General
7.6
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0221.

CVE-2022-3721
froxlor/froxlor General
7.6
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

CVE-2022-2982
vim/vim General
7.6
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0260.

CVE-2022-2901
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.1%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

CVE-2022-32503
Software Genérico General
7.6
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.