5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1899
radareorg/radare2 General
7.7
HIGH
EPSS
0.5%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2022-4291
Avast Antivirus Windows
7.7
HIGH
EPSS
0.2%
2022 CWE-119 1 PoC

The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component.

CVE-2022-25898
jsrsasign General
7.7
HIGH
EPSS
1.8%
2022 4 PoCs

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.

CVE-2022-0506
microweber/microweber Web
7.7
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0908
libtiff General
7.7
HIGH
EPSS
0.0%
2022 1 PoC

Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.

CVE-2022-22773
TIBCO JasperReports Server Web Cloud
7.7
HIGH
EPSS
0.6%
2022 1 PoC

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO JasperRepor

CVE-2022-28781
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

CVE-2022-1926
polonel/trudesk General
7.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-1238
radareorg/radare2 Web
7.6
HIGH
EPSS
0.3%
2022 CWE-787 2 PoCs

Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

CVE-2022-3721
froxlor/froxlor General
7.6
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

CVE-2022-21524
Solaris Operating System Database Windows
7.6
HIGH
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris as well as unauthorized update, insert or delete access to some of Oracle Solaris accessible data and unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base S

CVE-2022-4609
usememos/memos Web
7.6
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-39285
zoneminder Web
7.6
HIGH
EPSS
1.9%
2022 CWE-79 1 PoC

ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This then allows a malicious user to provide code that will execute when a user views the specific log on the "view=log" page. This vulnerability allows an attacker to store code within the logs that will be executed when loaded by a legitimate user. These actions will be performed with the permission of the victim. This could lead to data loss and/or further exploitation including accou

CVE-2022-1291
hhurz/tableexport.jquery.plugin Web
7.6
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party servers

CVE-2022-21649
convos Web
7.6
HIGH
EPSS
0.5%
2022 CWE-79 2 PoCs

Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

CVE-2022-4068
librenms/librenms Web
7.6
HIGH
EPSS
54.4%
2022 CWE-915 1 PoC

A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.

CVE-2022-2901
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.1%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

CVE-2022-4840
usememos/memos Web
7.6
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-0936
autolab/autolab Web
7.6
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.

CVE-2022-34453
XtremIO X2 General
7.6
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.