9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-28758
Zoom On-Premise Meeting Connector MMR General
8.2
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-48474
Control de Ciber General
8.2
HIGH
EPSS
1.7%
2022 CWE-400 1 PoC

Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process.

CVE-2022-0871
gogs/gogs General
8.2
HIGH
EPSS
1.0%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2022-33938
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.2%
2022 CWE-134 1 PoC

A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-32488
CPG BIOS General
8.2
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-26942
Mobile Radio General
8.2
HIGH
EPSS
0.1%
2022 CWE-822 1 PoC

The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with non-secure supervisor level code execution can exploit the issue in order to gain secure supervisor code execution within the TEE. This constitutes a full break of the TEE module, exposing the device key as well as any TETRA cryptographic keys and the confidential TETRA cryptographic primitives.

CVE-2022-41154
QUARTZ-GOLD General
8.2
HIGH
EPSS
1.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary file deletion. An attacker can send a network request to trigger this vulnerability.

CVE-2022-1774
jgraph/drawio General
8.2
HIGH
EPSS
0.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

CVE-2022-40261
Aptio General
8.2
HIGH
EPSS
0.1%
2022 CWE-120 1 PoC

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass securi

CVE-2022-4806
usememos/memos General
8.2
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-35877
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` configuration parameter, as used within the `testWifiAP` XCMD handler

CVE-2022-2306
heroiclabs/nakama General
8.2
HIGH
EPSS
0.2%
2022 CWE-613 1 PoC

Old session tokens can be used to authenticate to the application and send authenticated requests.

CVE-2022-38491
Software Genérico General
8.2
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.

CVE-2022-28759
Zoom On-Premise Meeting Connector MMR General
8.2
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-32489
CPG BIOS General
8.2
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-29181
nokogiri General
8.2
HIGH
EPSS
4.2%
2022 CWE-241 1 PoC

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.

CVE-2022-35876
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` and `key` configuration parameters, as used within the `testWifiAP` XCMD handler

CVE-2022-0991
admidio/admidio General
8.2
HIGH
EPSS
0.2%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.

CVE-2022-2313
Trellix Agent (TA) General
8.2
HIGH
EPSS
0.0%
2022 1 PoC

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

CVE-2022-35874
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `ssid` and `ssid_hex` configuration parameters, as used within the `testWifiAP` XCMD handler