2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-41837
OpenImageIO General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-562 1 PoC

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-44938
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

CVE-2022-27805
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
1.3%
2022 CWE-284 1 PoC

An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted network request can lead to arbitrary XCMD execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-46291
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MSI file format

CVE-2022-25767
com.bstek.ureport:ureport2-console General
9.8
CRITICAL
EPSS
3.1%
2022 1 PoC

All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

CVE-2022-43019
Software Genérico General
9.8
CRITICAL
EPSS
16.4%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

CVE-2022-21165
font-converter General
9.8
CRITICAL
EPSS
2.6%
2022 1 PoC

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

CVE-2022-46353
SCALANCE X204RNA (HSR) General
9.8
CRITICAL
EPSS
2.0%
2022 CWE-330 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.

CVE-2022-34668
NVIDIA FLARE General
9.8
CRITICAL
EPSS
22.4%
2022 CWE-502 1 PoC

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVE-2022-47714
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Last Yard 22.09.8-1 does not enforce HSTS headers

CVE-2022-43109
Software Genérico General
9.8
CRITICAL
EPSS
8.0%
2022 1 PoC

D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

CVE-2022-2631
tooljet/tooljet General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

CVE-2022-20472
Android General
9.8
CRITICAL
EPSS
4.5%
2022 1 PoC

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239210579

CVE-2022-47124
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.

CVE-2022-46597
Software Genérico General
9.8
CRITICAL
EPSS
12.2%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.

CVE-2022-45714
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.

CVE-2022-37434
Software Genérico General
9.8
CRITICAL
EPSS
92.7%
2022 8 PoCs

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

CVE-2022-45299
Software Genérico General
9.8
CRITICAL
EPSS
1.3%
2022 1 PoC

An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.

CVE-2022-46594
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function.

CVE-2022-40222
QUARTZ-GOLD General
9.8
CRITICAL
EPSS
3.6%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.