5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4694
usememos/memos Web
5.7
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-22323
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 218379.

CVE-2022-0245
livehelperchat/livehelperchat Web
5.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.

CVE-2022-29825
GX Works3 Cloud
5.6
MEDIUM
EPSS
0.2%
2022 CWE-259 1 PoC

Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, and MT Works2 versions from 1.100E to 1.200J allows an unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.

CVE-2022-25914
com.google.cloud.tools:jib-core DevOps Cloud
5.6
MEDIUM
EPSS
3.9%
2022 1 PoC

The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.

CVE-2022-3231
librenms/librenms Web
5.6
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.

CVE-2022-43978
Pandora FMS General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.

CVE-2022-3456
ikus060/rdiffweb General
5.6
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

CVE-2022-32484
CPG BIOS General
5.6
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2022-32483
CPG BIOS General
5.6
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2022-1172
gpac/gpac General
5.6
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-2366
Mattermost General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-276 1 PoC

Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.

CVE-2022-28193
Jetson AGX Xavier series, Jetson Xavier NX General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-35096
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

CVE-2022-3115
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.

CVE-2022-34710
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.7%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-0632
mruby/mruby General
5.5
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

CVE-2022-20494
Android General
5.5
MEDIUM
EPSS
1.8%
2022 1 PoC

In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243794204

CVE-2022-24823
netty Web Windows
5.5
MEDIUM
EPSS
0.4%
2022 CWE-668 1 PoC

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system tempora