9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7304
DLP ePO extension General
7.6
HIGH
EPSS
0.1%
2020 CWE-352 1 PoC

Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.

CVE-2020-25150
SpaceCom General
7.6
HIGH
EPSS
0.6%
2020 CWE-23 1 PoC

A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.

CVE-2020-26832
SAP NetWeaver AS ABAP (SAP Landscape Transformation) General
7.6
HIGH
EPSS
0.5%
2020 3 PoCs

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.

CVE-2018-21099
Software Genérico General
7.6
HIGH
EPSS
0.3%
2018 1 PoC

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

CVE-2018-6677
McAfee Web Gateway (MWG) General
7.6
HIGH
EPSS
0.5%
2018 1 PoC

Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to gain elevated privileges via unspecified vectors.

CVE-2018-21100
Software Genérico General
7.6
HIGH
EPSS
0.2%
2018 1 PoC

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

CVE-2022-1926
polonel/trudesk General
7.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-3721
froxlor/froxlor General
7.6
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

CVE-2022-2901
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.1%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

CVE-2022-34453
XtremIO X2 General
7.6
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.

CVE-2022-27835
Samsung Mobile Devices General
7.6
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVE-2022-32503
Software Genérico General
7.6
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.

CVE-2022-0881
chocobozzz/peertube General
7.6
HIGH
EPSS
0.5%
2022 CWE-922 1 PoC

Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.

CVE-2022-1812
publify/publify General
7.6
HIGH
EPSS
0.5%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.

CVE-2022-4506
openemr/openemr General
7.6
HIGH
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-2862
vim/vim General
7.6
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0221.

CVE-2022-2982
vim/vim General
7.6
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0260.

CVE-2022-1728
polonel/trudesk General
7.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVE-2022-37317
Software Genérico General
7.6
HIGH
EPSS
0.2%
2022 1 PoC

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2022-1021
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.3%
2022 CWE-922 1 PoC

Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.