7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3570
libtiff General
7.7
HIGH
EPSS
0.0%
2022 2 PoCs

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVE-2022-1427
mruby/mruby General
7.7
HIGH
EPSS
0.3%
2022 CWE-125 1 PoC

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

CVE-2022-27838
FactoryCamera General
7.7
HIGH
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

CVE-2022-38492
Software Genérico Database
7.7
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.

CVE-2022-0506
microweber/microweber Web
7.7
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-4291
Avast Antivirus Windows
7.7
HIGH
EPSS
0.2%
2022 CWE-119 1 PoC

The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component.

CVE-2022-0908
libtiff General
7.7
HIGH
EPSS
0.0%
2022 1 PoC

Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.

CVE-2022-1940
GitLab DevOps Web
7.7
HIGH
EPSS
0.2%
2022 1 PoC

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVE-2022-25647
com.google.code.gson:gson General
7.7
HIGH
EPSS
2.8%
2022 1 PoC

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVE-2022-42275
NVIDIA DGX servers General
7.7
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.

CVE-2022-25301
jsgui-lang-essentials General
7.7
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.

CVE-2022-35978
minetest General
7.7
HIGH
EPSS
13.7%
2022 CWE-693 1 PoC

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.

CVE-2022-22773
TIBCO JasperReports Server Web Cloud
7.7
HIGH
EPSS
0.6%
2022 1 PoC

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO JasperRepor

CVE-2022-0427
GitLab DevOps Web
7.7
HIGH
EPSS
0.1%
2022 1 PoC

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVE-2022-1213
livehelperchat/livehelperchat General
7.7
HIGH
EPSS
0.1%
2022 CWE-918 1 PoC

SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191

CVE-2022-28183
NVIDIA GPU Display Driver Windows
7.7
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure.

CVE-2022-1899
radareorg/radare2 General
7.7
HIGH
EPSS
0.5%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2022-2003
DirectLOGIC D0-06 series CPUs General
7.7
HIGH
EPSS
0.1%
2022 CWE-319 1 PoC

AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions pr

CVE-2022-48685
Software Genérico General
7.7
HIGH
EPSS
0.0%
2022 1 PoC

An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.

CVE-2022-22988
EdgeRover General
7.7
HIGH
EPSS
0.1%
2022 CWE-275 1 PoC

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated access to the device.