5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21195
url-regex General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash.

CVE-2022-3065
jgraph/drawio General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.

CVE-2022-28666
Custom Product Tabs for WooCommerce (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
8.8%
2022 CWE-287 0 PoCs

Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.

CVE-2022-1382
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.

CVE-2022-42254
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.3
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.

CVE-2022-21341
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM

CVE-2022-3298
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-32741
OTRS General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

CVE-2022-42265
NVIDIA GPU Display Driver for Linux General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering.

CVE-2022-33161
Security Directory Server Web
5.3
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

CVE-2022-2400
dompdf/dompdf General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

CVE-2022-21360
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enter

CVE-2022-0323
bobthecow/mustache.php Web
5.3
MEDIUM
EPSS
0.2%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

CVE-2022-28665
FreshTomato Web
5.3
MEDIUM
EPSS
4.0%
2022 CWE-787 1 PoC

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable URL-decoding feature that can lead to memory corruption.

CVE-2022-23003
Sweet B Library General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-703 1 PoC

When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output may cause an error when used in other operations. This may be leveraged by an attacker to cause an error scenario or incorrect choice of session key in applications which use the library, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components.

CVE-2022-3523
Kernel General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-119 1 PoC

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211020.

CVE-2022-21271
Solaris Operating System Database
5.3
MEDIUM
EPSS
1.9%
2022 2 PoCs

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise

CVE-2022-40691
SDS-3008 Series Industrial Ethernet Switch Web
5.3
MEDIUM
EPSS
1.3%
2022 CWE-200 2 PoCs

An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-25872
fast-string-search General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.

CVE-2022-44005
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.