5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38392
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2022 2 PoCs

Certain 5400 RPM hard drives, for laptops and other PCs in approximately 2005 and later, allow physically proximate attackers to cause a denial of service (device malfunction and system crash) via a resonant-frequency attack with the audio signal from the Rhythm Nation music video. A reported product is Seagate STDT4000100 763649053447.

CVE-2022-21540
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition

CVE-2022-3663
Bento4 General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-404 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212003.

CVE-2022-1036
microweber/microweber General
5.3
MEDIUM
EPSS
0.7%
2022 CWE-190 1 PoC

Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-3175
ikus060/rdiffweb General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-756 1 PoC

Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.

CVE-2022-4630
lirantal/daloradius Web
5.3
MEDIUM
EPSS
0.2%
2022 CWE-1004 1 PoC

Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.

CVE-2022-2309
lxml/lxml General
5.3
MEDIUM
EPSS
0.9%
2022 CWE-476 1 PoC

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that se

CVE-2022-1563
wp-graphql-woocommerce Web Windows
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

CVE-2022-37774
Software Genérico Web
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

CVE-2022-24723
URI.js Web
5.3
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

CVE-2022-45163
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2022 2 PoCs

An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for addi

CVE-2022-25622
SIMATIC CFU DIQ General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

CVE-2022-33932
PowerScale OneFS General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-419 1 PoC

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotected primary channel vulnerability. An unauthenticated network malicious attacker may potentially exploit this vulnerability, leading to a denial of filesystem services.

CVE-2022-25819
Samsung Mobile Devices with Exynos chipsets General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.

CVE-2022-23513
AdminLTE Web
5.3
MEDIUM
EPSS
9.2%
2022 CWE-284 1 PoC

Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.

CVE-2022-47715
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.

CVE-2022-45956
Software Genérico Web
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

CVE-2022-42258
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.3
MEDIUM
EPSS
0.0%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.

CVE-2022-3489
Wp-Hide Web Windows
5.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request