3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-4141
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVE-2022-0777
microweber/microweber General
7.3
HIGH
EPSS
0.5%
2022 CWE-640 1 PoC

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-29886
Alyac General
7.3
HIGH
EPSS
0.1%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-0849
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-21797
joblib General
7.3
HIGH
EPSS
0.3%
2022 1 PoC

The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

CVE-2022-0839
liquibase/liquibase General
7.3
HIGH
EPSS
0.2%
2022 CWE-611 3 PoCs

Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

CVE-2022-21658
rust General
7.3
HIGH
EPSS
0.9%
2022 CWE-363 1 PoC

Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't

CVE-2022-26310
Pandora FMS General
7.3
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation to access the privileges of a higher-level user or typically an admin user.

CVE-2022-3423
nocodb/nocodb General
7.3
HIGH
EPSS
1.1%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

CVE-2022-1073
Automatic Question Paper Generator General
7.3
HIGH
EPSS
0.3%
2022 CWE-640 1 PoC

A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

CVE-2022-1160
vim/vim General
7.3
HIGH
EPSS
0.6%
2022 CWE-122 1 PoC

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

CVE-2022-1031
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-1616
vim/vim General
7.3
HIGH
EPSS
0.2%
2022 CWE-416 2 PoCs

Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CVE-2022-1795
gpac/gpac General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-45101
PowerScale OneFS General
7.3
HIGH
EPSS
4.2%
2022 CWE-274 1 PoC

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution.

CVE-2022-3666
Bento4 General
7.3
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212006 is the identifier assigned to this vulnerability.

CVE-2022-4173
Avast and AVG Antivirus General
7.3
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.

CVE-2022-39858
FactoryCamera General
7.3
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.

CVE-2022-28194
Jetson AGX Xavier series, Jetson Xavier NX General
7.3
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-2927
notrinos/notrinoserp General
7.3
HIGH
EPSS
0.4%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.