3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-39907
Samsung Mobile Devices General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-190 1 PoC

Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVE-2022-0213
vim/vim General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-33730
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-787 1 PoC

Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.

CVE-2022-28810
🔥 KEV Software Genérico General
6.8
MEDIUM
EPSS
90.7%
2022 2 PoCs

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

CVE-2022-0695
radareorg/radare2 General
6.8
MEDIUM
EPSS
0.3%
2022 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-41564
TIBCO Hawk General
6.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO Operational Intelligence Hawk RedTail: versions 7.0.0 through 7.2.0.

CVE-2022-0158
vim/vim General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-4293
vim/vim General
6.8
MEDIUM
EPSS
0.3%
2022 CWE-1077 1 PoC

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

CVE-2022-39051
OTRS General
6.8
MEDIUM
EPSS
0.5%
2022 CWE-913 1 PoC

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

CVE-2022-1554
clinical-genomics/scout General
6.8
MEDIUM
EPSS
0.6%
2022 CWE-36 1 PoC

Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.

CVE-2022-1631
microweber/microweber General
6.8
MEDIUM
EPSS
11.7%
2022 CWE-284 2 PoCs

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would

CVE-2022-41333
FortiRecorder General
6.8
MEDIUM
EPSS
30.0%
2022 CWE-400 2 PoCs

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.

CVE-2022-0717
mruby/mruby General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-30624
Chcnav - P5E GNSS General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.

CVE-2022-39913
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.

CVE-2022-47930
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofing of messages easier. In particular, the Schnorr proof of knowledge implemented in sch.go does not utilize a session id, context, or random nonce in the generation of the challenge. This could allow a malicious user or an eavesdropper to replay a valid proof sent in the past.

CVE-2022-3349
PS4 General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-119 1 PoC

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

CVE-2022-1420
vim/vim General
6.8
MEDIUM
EPSS
0.6%
2022 CWE-823 2 PoCs

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.

CVE-2022-31898
Software Genérico General
6.8
MEDIUM
EPSS
22.4%
2022 2 PoCs

gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.

CVE-2022-0156
vim/vim General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-416 1 PoC

vim is vulnerable to Use After Free