5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-42285
NVIDIA DGX servers General
6.0
MEDIUM
EPSS
0.0%
2022 CWE-1231 1 PoC

DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, escalation of privileges, or data tampering.

CVE-2022-42286
NVIDIA DGX servers General
6.0
MEDIUM
EPSS
0.1%
2022 CWE-119 1 PoC

DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.

CVE-2022-29593
Software Genérico Web
5.9
MEDIUM
EPSS
8.2%
2022 4 PoCs

relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.

CVE-2022-43593
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability.

CVE-2022-45480
PC Keyboard WiFi & Bluetooth General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-26099
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVE-2022-26094
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-3590
WordPress Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
90.8%
2022 4 PoCs

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVE-2022-39879
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

CVE-2022-36867
Editor Lite General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.

CVE-2022-31133
humhub Web
5.9
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of individual "spaces" are not properly escaped and so an attacker with sufficient privilege could insert malicious javascript into a space name and exploit system users who visit that space. It is recommended that the HumHub is upgraded to 1.11.4, 1.10.5. There are no known workarounds for this issue.

CVE-2022-0419
radareorg/radare2 General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-36873
com.samsung.android.waterplugin General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.

CVE-2022-39861
FactoryCamera General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.

CVE-2022-26095
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-4304
OpenSSL General
5.9
MEDIUM
EPSS
0.2%
2022 1 PoC

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server cou

CVE-2022-4644
ikus060/rdiffweb General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.

CVE-2022-43293
Software Genérico Windows
5.9
MEDIUM
EPSS
3.5%
2022 2 PoCs

Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \Wacom\Wacom_Tablet.exe.

CVE-2022-21211
posix General
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the value of toString is not invokable (not a function), and then it will crash with type-check.

CVE-2022-21493
Solaris Operating System Database
5.9
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeat