5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-32832
macOS General
6.7
MEDIUM
EPSS
8.9%
2022 2 PoCs

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVE-2022-31239
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.1%
2022 CWE-532 1 PoC

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.

CVE-2022-30573
TIBCO FTL - Community Edition General
6.7
MEDIUM
EPSS
0.5%
2022 1 PoC

The ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.0.0 through 6.8.0, TIBCO FTL - Developer Edition: versions 6.0.1 through 6.8.0, TIBCO FTL - Enterprise Edition: versions 6.0.0 through 6.7.3, and TIBCO FTL - Enterprise Edi

CVE-2022-34757
Easergy P5 Networking
6.7
MEDIUM
EPSS
0.2%
2022 CWE-327 1 PoC

A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between Easergy Pro software and the device, which may allow an attacker to observe protected communication details. Affected Products: Easergy P5 (V01.401.102 and prior)

CVE-2022-29170
grafana DevOps Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-601 1 PoC

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a p

CVE-2022-36875
com.samsung.android.waterplugin General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.

CVE-2022-1674
vim/vim General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-476 2 PoCs

NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.

CVE-2022-4721
ikus060/rdiffweb General
6.6
MEDIUM
EPSS
0.3%
2022 CWE-75 1 PoC

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.

CVE-2022-1629
vim/vim General
6.6
MEDIUM
EPSS
0.5%
2022 CWE-126 2 PoCs

Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution

CVE-2022-36869
com.android.providers.contacts General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.

CVE-2022-1297
radareorg/radare2 General
6.6
MEDIUM
EPSS
0.3%
2022 CWE-125 1 PoC

Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

CVE-2022-2923
vim/vim General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.

CVE-2022-2279
bfabiszewski/libmobi General
6.6
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.

CVE-2022-0263
pimcore/pimcore General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

CVE-2022-21399
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-1725
vim/vim General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-476 2 PoCs

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.

CVE-2022-1283
radareorg/radare2 General
6.6
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).

CVE-2022-1533
bfabiszewski/libmobi General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.

CVE-2022-1735
vim/vim General
6.6
MEDIUM
EPSS
0.2%
2022 CWE-120 2 PoCs

Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.