7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0245
livehelperchat/livehelperchat Web
5.7
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.

CVE-2022-3516
librenms/librenms Web
5.7
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-0268
getgrav/grav Web
5.7
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.

CVE-2022-32484
CPG BIOS General
5.6
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2022-29825
GX Works3 Cloud
5.6
MEDIUM
EPSS
0.2%
2022 CWE-259 1 PoC

Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, and MT Works2 versions from 1.100E to 1.200J allows an unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.

CVE-2022-25914
com.google.cloud.tools:jib-core DevOps Cloud
5.6
MEDIUM
EPSS
3.9%
2022 1 PoC

The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.

CVE-2022-3231
librenms/librenms Web
5.6
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.

CVE-2022-28193
Jetson AGX Xavier series, Jetson Xavier NX General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-3456
ikus060/rdiffweb General
5.6
MEDIUM
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

CVE-2022-2366
Mattermost General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-276 1 PoC

Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.

CVE-2022-1172
gpac/gpac General
5.6
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-43978
Pandora FMS General
5.6
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.

CVE-2022-32483
CPG BIOS General
5.6
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2022-30155
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2022 1 PoC

Windows Kernel Denial of Service Vulnerability

CVE-2022-21375
Solaris Operating System Database
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-25814
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVE-2022-40884
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Bento4 1.6.0 has memory leaks via the mp4fragment.

CVE-2022-0762
microweber/microweber General
5.5
MEDIUM
EPSS
0.2%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-24483
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
5.9%
2022 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2022-3115
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.