7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-32832
macOS General
6.7
MEDIUM
EPSS
8.9%
2022 2 PoCs

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVE-2022-0362
star7th/showdoc Database
6.7
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

CVE-2022-3859
Trellix Agent General
6.7
MEDIUM
EPSS
0.2%
2022 1 PoC

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

CVE-2022-30121
Ivanti Endpoint Manager General
6.7
MEDIUM
EPSS
0.1%
2022 1 PoC

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

CVE-2022-2874
vim/vim General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0224.

CVE-2022-1296
radareorg/radare2 General
6.6
MEDIUM
EPSS
0.3%
2022 CWE-125 1 PoC

Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

CVE-2022-0262
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

CVE-2022-0285
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

CVE-2022-2279
bfabiszewski/libmobi General
6.6
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.

CVE-2022-0509
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

CVE-2022-36875
com.samsung.android.waterplugin General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.

CVE-2022-27822
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

CVE-2022-1733
vim/vim General
6.6
MEDIUM
EPSS
0.1%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.

CVE-2022-0341
vanessa219/vditor Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.

CVE-2022-0263
pimcore/pimcore General
6.6
MEDIUM
EPSS
0.0%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

CVE-2022-1629
vim/vim General
6.6
MEDIUM
EPSS
0.5%
2022 CWE-126 2 PoCs

Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution

CVE-2022-21399
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-25785
SiteManager General
6.6
MEDIUM
EPSS
1.1%
2022 CWE-121 1 PoC

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVE-2022-1720
vim/vim General
6.6
MEDIUM
EPSS
0.5%
2022 CWE-126 4 PoCs

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.