5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2752
GateManager General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

CVE-2022-28190
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service.

CVE-2022-42821
macOS General
5.5
MEDIUM
EPSS
0.0%
2022 2 PoCs

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

CVE-2022-1056
libtiff General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.

CVE-2022-31902
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

CVE-2022-21509
MySQL Server Database
5.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CV

CVE-2022-3114
Kernel General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return value of kcalloc() and will cause the null pointer dereference.

CVE-2022-34682
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager),NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-21425
MySQL Server Database
5.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vec

CVE-2022-0924
libtiff General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

CVE-2022-29799
networkd-dispatcher General
5.5
MEDIUM
EPSS
0.5%
2022 CWE-22 1 PoC

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.

CVE-2022-2644
Online Admission System Database
5.5
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some unknown processing of the component GET Parameter Handler. The manipulation of the argument eid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-205565 was assigned to this vulnerability.

CVE-2022-4786
Video.js Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4448
GiveWP Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-3934
FlatPM Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
4.9%
2022 1 PoC

The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-45472
Software Genérico Web
5.4
MEDIUM
EPSS
1.1%
2022 1 PoC

CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

CVE-2022-43770
Pentaho Business Analytics Server Web
5.4
MEDIUM
EPSS
0.4%
2022 CWE-863 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   

CVE-2022-21238
InRouter302 Web Networking
5.4
MEDIUM
EPSS
2.0%
2022 CWE-80 1 PoC

A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1850
filegator/filegator General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.

CVE-2022-42069
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.