7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36870
Samsung Pay General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

CVE-2022-4222
Canteen Management System Web Database
5.0
MEDIUM
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipulation of the argument search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214523.

CVE-2022-4317
DAST DevOps
5.0
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.

CVE-2022-36871
Samsung Pay General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

CVE-2022-21147
Alyac General
5.0
MEDIUM
EPSS
0.2%
2022 CWE-823 1 PoC

An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-crafted PE file can trigger this vulnerability to cause denial of service and termination of malware scan. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2886
Laravel Web
5.0
MEDIUM
EPSS
0.4%
2022 CWE-502 1 PoC

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

CVE-2022-3705
vim General
5.0
MEDIUM
EPSS
0.5%
2022 CWE-119 1 PoC

A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324.

CVE-2022-22265
🔥 KEV Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.2%
2022 CWE-703 1 PoC

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

CVE-2022-36872
Samsung Pay General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

CVE-2022-0870
gogs/gogs General ⚡ nuclei
5.0
MEDIUM
EPSS
9.1%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2022-3216
Game Boy Color General
5.0
MEDIUM
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability has been found in Nintendo Game Boy Color and classified as problematic. This vulnerability affects unknown code of the component Mobile Adapter GB. The manipulation leads to memory corruption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-208606 is the identifier assigned to this vulnerability.

CVE-2022-4248
Movie Ticket Booking System Web Database
5.0
MEDIUM
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVE-2022-3733
Web-Based Student Clearance System Web Database
5.0
MEDIUM
EPSS
0.2%
2022 CWE-707 2 PoCs

A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This affects an unknown part of the file Admin/edit-admin.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212415.

CVE-2022-43665
Alyac General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-823 1 PoC

A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-crafted PE file can lead to killing target process. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-28197
Jetson AGX Xavier series, Jetson Xavier NX General
5.0
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted data may allow a highly privileged local attacker to cause an integer overflow. This difficult-to-exploit vulnerability may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

CVE-2022-3714
Online Medicine Ordering System Database
5.0
MEDIUM
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. VDB-212346 is the identifier assigned to this vulnerability.

CVE-2022-28780
Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

CVE-2022-3414
Web-Based Student Clearance System Web Database
5.0
MEDIUM
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of the argument txtusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-210246 is the identifier assigned to this vulnerability.

CVE-2022-4613
Passwordstate General
5.0
MEDIUM
EPSS
0.3%
2022 CWE-266 2 PoCs

A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216275.

CVE-2022-4206
DAST API scanner Web
5.0
MEDIUM
EPSS
0.2%
2022 1 PoC

A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report