5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27838
FactoryCamera General
7.7
HIGH
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

CVE-2022-25647
com.google.code.gson:gson General
7.7
HIGH
EPSS
2.8%
2022 1 PoC

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVE-2022-1071
mruby/mruby General
7.7
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-25301
jsgui-lang-essentials General
7.7
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.

CVE-2022-2003
DirectLOGIC D0-06 series CPUs General
7.7
HIGH
EPSS
0.1%
2022 CWE-319 1 PoC

AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions pr

CVE-2022-1427
mruby/mruby General
7.7
HIGH
EPSS
0.3%
2022 CWE-125 1 PoC

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

CVE-2022-1213
livehelperchat/livehelperchat General
7.7
HIGH
EPSS
0.1%
2022 CWE-918 1 PoC

SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191

CVE-2022-22988
EdgeRover General
7.7
HIGH
EPSS
0.1%
2022 CWE-275 1 PoC

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated access to the device.

CVE-2022-1940
GitLab DevOps Web
7.7
HIGH
EPSS
0.2%
2022 1 PoC

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVE-2022-42275
NVIDIA DGX servers General
7.7
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.

CVE-2022-35978
minetest General
7.7
HIGH
EPSS
13.7%
2022 CWE-693 1 PoC

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.

CVE-2022-21382
Enterprise Session Border Controller Web Database
7.7
HIGH
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. While the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterp

CVE-2022-48685
Software Genérico General
7.7
HIGH
EPSS
0.0%
2022 1 PoC

An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.

CVE-2022-28183
NVIDIA GPU Display Driver Windows
7.7
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure.

CVE-2022-38492
Software Genérico Database
7.7
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.

CVE-2022-3570
libtiff General
7.7
HIGH
EPSS
0.0%
2022 2 PoCs

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVE-2022-0895
microweber/microweber General
7.7
HIGH
EPSS
1.2%
2022 CWE-96 1 PoC

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0427
GitLab DevOps Web
7.7
HIGH
EPSS
0.1%
2022 1 PoC

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVE-2022-22264
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.

CVE-2022-50976
VibroLine Configurator 5.0 General
7.7
HIGH
EPSS
0.0%
2022 CWE-1288 2 PoCs

A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.