7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2752
GateManager General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

CVE-2022-1507
hpjansson/chafa General
5.5
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.

CVE-2022-35094
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.

CVE-2022-0890
mruby/mruby General
5.5
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-3105
Kernel Web
5.5
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. uapi_finalize in drivers/infiniband/core/uverbs_uapi.c lacks check of kmalloc_array().

CVE-2022-48310
Sophos Connect Client General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.

CVE-2022-34677
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.5
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.

CVE-2022-3110
Kernel General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. _rtw_init_xmit_priv in drivers/staging/r8188eu/core/rtw_xmit.c lacks check of the return value of rtw_alloc_hwxmits() and will cause the null pointer dereference.

CVE-2022-34679
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to a null-pointer dereference, which may lead to denial of service.

CVE-2022-21367
MySQL Server Database
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Avai

CVE-2022-28191
NVIDIA Virtual GPU Software and NVIDIA Cloud Gaming Cloud
5.5
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.

CVE-2022-42866
tvOS General
5.5
MEDIUM
EPSS
0.1%
2022 4 PoCs

The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.

CVE-2022-4479
Table of Contents Plus Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-42069
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.

CVE-2022-41542
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

devhub 0.102.0 was discovered to contain a broken session control.

CVE-2022-4832
Store Locator WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3933
Essential Real Estate Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
5.5%
2022 1 PoC

The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.

CVE-2022-26950
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

CVE-2022-4762
Materialis Companion Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Materialis Companion WordPress plugin before 1.3.40 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-28286
Thunderbird General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.