9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-21191
global-modules-path General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

CVE-2022-25890
wifey General
7.4
HIGH
EPSS
1.5%
2022 CWE-78 1 PoC

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

CVE-2022-1155
snipe/snipe-it General
7.4
HIGH
EPSS
0.3%
2022 CWE-840 1 PoC

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

CVE-2022-25916
mt7688-wiscan General
7.4
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

CVE-2022-24377
cycle-import-check General
7.4
HIGH
EPSS
1.4%
2022 1 PoC

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

CVE-2022-26092
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

CVE-2022-25962
vagrant.js General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

CVE-2022-0432
mastodon/mastodon General ⚡ nuclei
7.4
HIGH
EPSS
57.1%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

CVE-2022-1253
strukturag/libde265 General
7.4
HIGH
EPSS
0.5%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

CVE-2022-25171
p4 General
7.4
HIGH
EPSS
1.9%
2022 1 PoC

The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

CVE-2022-1809
radareorg/radare2 General
7.4
HIGH
EPSS
0.3%
2022 CWE-824 1 PoC

Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2022-25350
puppet-facter General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

CVE-2022-25853
semver-tags General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.

CVE-2022-24860
databasir General
7.4
HIGH
EPSS
0.3%
2022 CWE-321 1 PoC

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at different IP addresses.

CVE-2022-47630
Software Genérico General
7.4
HIGH
EPSS
0.6%
2022 1 PoC

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

CVE-2022-25908
create-choo-electron General
7.4
HIGH
EPSS
1.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-21129
nemo-appium General
7.4
HIGH
EPSS
1.1%
2022 CWE-78 1 PoC

Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.

CVE-2022-25923
exec-local-bin General
7.4
HIGH
EPSS
1.6%
2022 CWE-78 1 PoC

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

CVE-2022-25926
window-control General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

CVE-2022-29217
pyjwt General
7.4
HIGH
EPSS
0.4%
2022 CWE-327 1 PoC

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always