14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-46293
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC file format, inside the Final Point and Derivatives section

CVE-2022-45720
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function.

CVE-2022-45482
Lazy Mouse General
9.8
CRITICAL
EPSS
1.9%
2022 CWE-521 1 PoC

Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-3980
Sophos Mobile managed on-premises General ⚡ nuclei
9.8
CRITICAL
EPSS
88.0%
2022 0 PoCs

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

CVE-2022-47035
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

CVE-2022-25235
Software Genérico General
9.8
CRITICAL
EPSS
13.3%
2022 2 PoCs

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

CVE-2022-46289
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-122 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.nAtoms calculation wrap-around, leading to a small buffer allocation

CVE-2022-38580
Software Genérico General
9.8
CRITICAL
EPSS
48.8%
2022 1 PoC

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

CVE-2022-50981
VibroLine VLX1 HD 5.0 General
9.8
CRITICAL
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

CVE-2022-2143
iView General
9.8
CRITICAL
EPSS
58.3%
2022 CWE-77 1 PoC

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2022-42948
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
21.8%
2022 2 PoCs

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CVE-2022-2821
namelessmc/nameless General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-304 1 PoC

Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

CVE-2022-42842
macOS General
9.8
CRITICAL
EPSS
4.1%
2022 6 PoCs

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVE-2022-44251
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

CVE-2022-46580
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.

CVE-2022-3268
ikus060/minarca General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

CVE-2022-44187
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

CVE-2022-32504
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-46598
Software Genérico General
9.8
CRITICAL
EPSS
16.6%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.

CVE-2022-40916
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2022 2 PoCs

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.