3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2279
bfabiszewski/libmobi General
6.6
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.

CVE-2022-1629
vim/vim General
6.6
MEDIUM
EPSS
0.5%
2022 CWE-126 2 PoCs

Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution

CVE-2022-0263
pimcore/pimcore General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

CVE-2022-38751
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-50979
VibroLine VLX1 HD 5.0 General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

CVE-2022-28291
Nessus Professional General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The vulnerability allows an attacker to access credentials stored in Nessus scanners, potentially compromising its customers’ network of assets.

CVE-2022-26385
Firefox General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 98.

CVE-2022-38970
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.

CVE-2022-0686
unshiftio/url-parse General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

CVE-2022-35063
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41a8.

CVE-2022-50980
VibroLine VLX1 HD 5.0 General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-306 2 PoCs

A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.

CVE-2022-35037
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.

CVE-2022-38749
SnakeYAML General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-35031
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.

CVE-2022-35067
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b0.

CVE-2022-38752
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.

CVE-2022-35047
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05aa.

CVE-2022-46378
uC-FTPs General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-823 1 PoC

An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no port argument is provided to the `PORT` command.

CVE-2022-44268
Software Genérico General
6.5
MEDIUM
EPSS
88.5%
2022 29 PoCs

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

CVE-2022-41274
Disclosure Management General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-863 1 PoC

SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can lead to the exposure of data like financial reports.