7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25743
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
8.4
HIGH
EPSS
0.1%
2022 1 PoC

Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-0443
vim/vim General
8.4
HIGH
EPSS
0.2%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 8.2.

CVE-2022-33147
AVideo Web Database
8.3
HIGH
EPSS
3.0%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the aVideoEncoder functionality which can be used to add new videos, allowing an attacker to inject SQL by manipulating the videoDownloadedLink or duration parameter.

CVE-2022-4691
usememos/memos Web
8.3
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-4847
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-941 1 PoC

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1727
jgraph/drawio General
8.3
HIGH
EPSS
1.1%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.

CVE-2022-0224
dolibarr/dolibarr Database
8.3
HIGH
EPSS
0.5%
2022 CWE-89 1 PoC

dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CVE-2022-21134
Software Genérico Web
8.3
HIGH
EPSS
0.4%
2022 CWE-347 1 PoC

A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-4865
usememos/memos Web
8.3
HIGH
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1813
yogeshojha/rengine General
8.3
HIGH
EPSS
11.4%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.

CVE-2022-4849
usememos/memos Web
8.3
HIGH
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1471
SnakeYAML General
8.3
HIGH
EPSS
93.8%
2022 CWE-20 2 PoCs

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVE-2022-1285
gogs/gogs General
8.3
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

CVE-2022-0258
pimcore/pimcore Database
8.3
HIGH
EPSS
0.0%
2022 CWE-89 1 PoC

pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CVE-2022-2732
openemr/openemr General
8.3
HIGH
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-37397
Yugabyte DB Windows
8.3
HIGH
EPSS
0.5%
2022 CWE-287 1 PoC

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

CVE-2022-33148
AVideo Web Database
8.3
HIGH
EPSS
2.5%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the title parameter.

CVE-2022-31176
grafana-image-renderer DevOps Web
8.3
HIGH
EPSS
0.6%
2022 CWE-200 1 PoC

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana). All Grafana installations should be upgraded to version 3.6.1 as soon as possible. As a workaround it is possible to [disable HTTP remote rendering](https://grafana.com/docs/grafana/latest/setup-graf

CVE-2022-4809
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-33149
AVideo Web Database
8.3
HIGH
EPSS
3.2%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the CloneSite plugin, allowing an attacker to inject SQL by manipulating the url parameter.