3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-25876
link-preview-js General
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

CVE-2022-28792
Gear IconX PC Manager General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.

CVE-2022-39846
Smart Switch PC General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.

CVE-2022-0696
vim/vim General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-476 2 PoCs

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

CVE-2022-43588
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-33702
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.

CVE-2022-43590
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-30722
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

CVE-2022-38201
ArcGIS Quickcapture General
6.1
MEDIUM
EPSS
0.4%
2022 CWE-601 1 PoC

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVE-2022-28923
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
2.9%
2022 0 PoCs

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

CVE-2022-4720
ikus060/rdiffweb General
6.1
MEDIUM
EPSS
0.1%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.

CVE-2022-3153
vim/vim General
6.1
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.

CVE-2022-2390
Play Services SDK General
6.1
MEDIUM
EPSS
0.0%
2022 CWE-471 1 PoC

Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.

CVE-2022-0645
posthog/posthog General
6.1
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.

CVE-2022-45413
Firefox General
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

CVE-2022-21970
Microsoft Edge (Chromium-based) General
6.1
MEDIUM
EPSS
2.3%
2022 1 PoC

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVE-2022-45418
Firefox ESR General
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVE-2022-41260
SAP Financial Consolidation General
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.