5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0717
mruby/mruby General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-29833
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.3%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could access to MELSEC safety CPU modules illgally.

CVE-2022-28185
NVIDIA GPU Display Driver Windows
6.8
MEDIUM
EPSS
0.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.

CVE-2022-0911
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-41333
FortiRecorder General
6.8
MEDIUM
EPSS
30.0%
2022 CWE-400 2 PoCs

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.

CVE-2022-47930
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofing of messages easier. In particular, the Schnorr proof of knowledge implemented in sch.go does not utilize a session id, context, or random nonce in the generation of the challenge. This could allow a malicious user or an eavesdropper to replay a valid proof sent in the past.

CVE-2022-29827
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.5%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project files or execute programs illegally.

CVE-2022-3255
pimcore/pimcore General
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.

CVE-2022-3278
vim/vim General
6.8
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.

CVE-2022-0893
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-29829
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.3%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, Motion Control Setting(GX Works3 related software) versions from 1.035M to 1.042U, and MT Works2 versions from 1.100E to 1.200J allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.

CVE-2022-46367
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.

CVE-2022-21551
GoldenGate Web Database
6.8
MEDIUM
EPSS
1.6%
2022 1 PoC

Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate). The supported version that is affected is 21c: prior to 21.7.0.0.0; 19c: prior to 19.1.0.0.220719. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CVE-2022-29828
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.5%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project file or execute programs illegally.

CVE-2022-0571
phoronix-test-suite/phoronix-test-suite Web
6.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.

CVE-2022-3349
PS4 General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-119 1 PoC

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

CVE-2022-2016
neorazorx/facturascripts Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.

CVE-2022-0156
vim/vim General
6.8
MEDIUM
EPSS
0.2%
2022 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2022-29826
GX Works3 Cloud
6.8
MEDIUM
EPSS
0.1%
2022 CWE-312 1 PoC

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.

CVE-2022-1163
mineweb/minewebcms Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 3 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.