3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-26948
Software Genérico General
5.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.

CVE-2022-43473
OpManager General
5.8
MEDIUM
EPSS
35.6%
2022 CWE-611 1 PoC

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

CVE-2022-45835
PhonePe Payment Solutions General ⚡ nuclei
5.8
MEDIUM
EPSS
71.1%
2022 CWE-918 0 PoCs

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

CVE-2022-2196
Linux Kernel General
5.8
MEDIUM
EPSS
0.0%
2022 CWE-1188 1 PoC

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit 2e7eab81425a

CVE-2022-4719
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.4%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

CVE-2022-22284
Samsung Internet General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

CVE-2022-0407
vim/vim General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-3290
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-130 1 PoC

Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-30625
Chcnav - P5E GNSS General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-548 1 PoC

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

CVE-2022-28195
Jetson AGX Xavier series, Jetson Xavier NX General
5.7
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

CVE-2022-39899
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

CVE-2022-2549
gpac/gpac General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-38124
SiteManager General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-267 1 PoC

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

CVE-2022-26091
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.

CVE-2022-3438
ikus060/rdiffweb General
5.7
MEDIUM
EPSS
0.3%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

CVE-2022-30627
Chcnav - P5E GNSS General
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the existing user passwords on their operating systems and passwords.

CVE-2022-2366
Mattermost General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-276 1 PoC

Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.

CVE-2022-32484
CPG BIOS General
5.6
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2022-32483
CPG BIOS General
5.6
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2022-3456
ikus060/rdiffweb General
5.6
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.