5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0253
livehelperchat/livehelperchat Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-47578
Software Genérico Windows
7.1
HIGH
EPSS
0.0%
2022 1 PoC

An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by booting into Safe Mode. This allows a file to be exchanged outside the laptop/system. Safe Mode can be launched by any user (even without admin rights). Data exfiltration can occur, and also malware might be introduced onto the system. NOTE: the vendor's position is "it's not a vulnerability in our p

CVE-2022-41742
NGINX Web
7.1
HIGH
EPSS
0.1%
2022 CWE-787 1 PoC

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigge

CVE-2022-42262
vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
7.1
HIGH
EPSS
0.1%
2022 CWE-787 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

CVE-2022-42263
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
7.1
HIGH
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an Integer overflow may lead to denial of service or information disclosure.

CVE-2022-2134
inventree/inventree General
7.1
HIGH
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

CVE-2022-3179
ikus060/rdiffweb General
7.1
HIGH
EPSS
0.3%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.

CVE-2022-45365
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
20.1%
2022 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

CVE-2022-22292
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2022 CWE-280 1 PoC

Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

CVE-2022-31250
Tumbleweed General
7.1
HIGH
EPSS
0.1%
2022 CWE-59 1 PoC

A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.

CVE-2022-42855
tvOS General
7.1
HIGH
EPSS
0.1%
2022 6 PoCs

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

CVE-2022-2098
kromitgmbh/titra General
7.1
HIGH
EPSS
0.3%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.

CVE-2022-20822
Cisco Identity Services Engine Software Web Networking
7.1
HIGH
EPSS
0.5%
2022 CWE-22 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to. Cisco plans to release softw

CVE-2022-42264
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
7.1
HIGH
EPSS
0.1%
2022 CWE-823 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service.

CVE-2022-0378
microweber/microweber Web ⚡ nuclei
7.1
HIGH
EPSS
7.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-31192
DSpace Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2022-1886
vim/vim General
7.1
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-4294
Norton Antivirus Windows Eraser Engine Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2022-0956
star7th/showdoc Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

CVE-2022-34388
SupportAssist General
7.1
HIGH
EPSS
0.1%
2022 CWE-318 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.