9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-43941
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.4%
2022 CWE-611 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

CVE-2022-1201
mruby/mruby General
7.1
HIGH
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.

CVE-2022-35880
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `NewInternalClient` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-25989
Eufy Homebase 2 General
7.1
HIGH
EPSS
0.1%
2022 CWE-290 1 PoC

An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.

CVE-2022-0755
salesagility/suitecrm General
7.1
HIGH
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

CVE-2022-41221
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 1 PoC

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

CVE-2022-0580
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-863 1 PoC

Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-28753
Zoom On-Premise Meeting Connector MMR General
7.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-35953
bookwyrm General
7.1
HIGH
EPSS
0.3%
2022 CWE-601 1 PoC

BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to read next. Some links in BookWyrm may be vulnerable to tabnabbing, a form of phishing that gives attackers an opportunity to redirect a user to a malicious site. The issue was patched in version 0.4.5.

CVE-2022-2653
plankanban/planka General
7.1
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able to read any file in the system.

CVE-2022-0139
radareorg/radare2 General
7.1
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-33926
Wyse Management Suite General
7.1
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.

CVE-2022-2134
inventree/inventree General
7.1
HIGH
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

CVE-2022-3179
ikus060/rdiffweb General
7.1
HIGH
EPSS
0.3%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.

CVE-2022-22292
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2022 CWE-280 1 PoC

Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

CVE-2022-31250
Tumbleweed General
7.1
HIGH
EPSS
0.1%
2022 CWE-59 1 PoC

A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.

CVE-2022-42855
tvOS General
7.1
HIGH
EPSS
0.1%
2022 6 PoCs

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

CVE-2022-2098
kromitgmbh/titra General
7.1
HIGH
EPSS
0.3%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.

CVE-2022-1886
vim/vim General
7.1
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-34388
SupportAssist General
7.1
HIGH
EPSS
0.1%
2022 CWE-318 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.