5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4843
radareorg/radare2 General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2.

CVE-2022-22563
PowerScale OneFS General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-223 1 PoC

Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.

CVE-2022-36841
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-39853
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-416 1 PoC

A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-23426
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-94 1 PoC

A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

CVE-2022-36925
Zoom Rooms for macOS General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-321 1 PoC

Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service.

CVE-2022-36862
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-39860
QuickShare General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast.

CVE-2022-25332
OMAP General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-208 1 PoC

The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managing cache contents and collecting timing information for different ciphertext inputs. Using this side channel, the SK_LOAD secure kernel routine can be used to recover the Customer Encryption Key (CEK).

CVE-2022-21522
MySQL Server Database
4.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-21625
MySQL Server Database
4.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-4612
Passwordstate General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-522 2 PoCs

A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerability affects unknown code. The manipulation leads to insufficiently protected credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. VDB-216274 is the identifier assigned to this vulnerability.

CVE-2022-46890
Software Genérico Web
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).

CVE-2022-0906
microweber/microweber Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.

CVE-2022-23433
Reminder General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.

CVE-2022-1350
GhostPCL General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.

CVE-2022-1416
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVE-2022-3514
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVE-2022-3585
Simple Cold Storage Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-863 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-211194 is the identifier assigned to this vulnerability.

CVE-2022-3245
microweber/microweber Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-94 1 PoC

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.