7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

CVE-2022-28779
Samsung Android USB Driver windows installer Windows
5.3
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.

CVE-2022-0713
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-35739
Software Genérico Web
5.3
MEDIUM
EPSS
1.2%
2022 1 PoC

PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.

CVE-2022-42127
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.

CVE-2022-42257
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.3
MEDIUM
EPSS
0.0%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service.

CVE-2022-32741
OTRS General
5.3
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

CVE-2022-42265
NVIDIA GPU Display Driver for Linux General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering.

CVE-2022-39881
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.6%
2022 CWE-20 1 PoC

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.

CVE-2022-23814
3rd Gen EPYC General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.

CVE-2022-1563
wp-graphql-woocommerce Web Windows
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

CVE-2022-33161
Security Directory Server Web
5.3
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

CVE-2022-2400
dompdf/dompdf General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

CVE-2022-22409
Aspera Faspex General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.

CVE-2022-1815
jgraph/drawio General ⚡ nuclei
5.3
MEDIUM
EPSS
24.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

CVE-2022-2930
octoprint/octoprint General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-38392
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2022 2 PoCs

Certain 5400 RPM hard drives, for laptops and other PCs in approximately 2005 and later, allow physically proximate attackers to cause a denial of service (device malfunction and system crash) via a resonant-frequency attack with the audio signal from the Rhythm Nation music video. A reported product is Seagate STDT4000100 763649053447.

CVE-2022-21360
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enter

CVE-2022-0323
bobthecow/mustache.php Web
5.3
MEDIUM
EPSS
0.2%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.