9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-45059
Software Genérico General
7.5
HIGH
EPSS
1.5%
2022 1 PoC

An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.

CVE-2022-25904
safe-eval General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype.

CVE-2022-1722
jgraph/drawio General
7.5
HIGH
EPSS
0.2%
2022 CWE-918 1 PoC

SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses

CVE-2022-26303
OAS Platform General
7.5
HIGH
EPSS
0.3%
2022 CWE-306 1 PoC

An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-42733
syngo Dynamics General
7.5
HIGH
EPSS
0.3%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.

CVE-2022-42124
Software Genérico General
7.5
HIGH
EPSS
1.2%
2022 2 PoCs

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.

CVE-2022-27673
AMD Link Android General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.

CVE-2022-45546
Software Genérico General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for authentication via network sniffing.

CVE-2022-26043
OAS Platform General
7.5
HIGH
EPSS
0.3%
2022 CWE-306 1 PoC

An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-36324
RUGGEDCOM RM1224 LTE(4G) EU General
7.5
HIGH
EPSS
1.5%
2022 CWE-770 1 PoC

Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.

CVE-2022-1444
radareorg/radare2 General
7.5
HIGH
EPSS
0.3%
2022 CWE-416 2 PoCs

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service.

CVE-2022-24381
ASNeG/OpcUaStack General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-47075
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
92.1%
2022 3 PoCs

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

CVE-2022-41404
Software Genérico General
7.5
HIGH
EPSS
0.8%
2022 2 PoCs

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVE-2022-44356
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
47.1%
2022 0 PoCs

WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.

CVE-2022-25882
onnx General
7.5
HIGH
EPSS
5.8%
2022 CWE-22 1 PoC

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

CVE-2022-31474
BackupBuddy General ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2022 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

CVE-2022-46432
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

An exploitable firmware modification vulnerability was discovered on TP-Link TL-WR743ND V1. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v3.12.20 and earlier.

CVE-2022-24298
FreeOpcUa/freeopcua General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-42734
syngo Dynamics General
7.5
HIGH
EPSS
0.2%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.