3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-29865
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 2 PoCs

OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

CVE-2022-1342
Remote Desktop Manager General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-549 1 PoC

A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.

CVE-2022-28382
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 14 PoCs

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The firmware of the USB-to-SATA bridge controller INIC-3637EN uses AES-256 with the ECB mode. This operation mode of block ciphers (e.g., AES) always encrypts identical plaintext data, in this case blocks of 16 bytes, to identical ciphertext data. For some data, for instance bitmap images, the lack of the cryptographic pro

CVE-2022-30328
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.

CVE-2022-28480
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

CVE-2022-28217
SAP NetWeaver (EP Web Page Composer) General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-918 1 PoC

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.

CVE-2022-29729
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVE-2022-31201
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

SoftGuard Web (SGW) before 5.1.5 allows HTML injection.

CVE-2022-37123
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.

CVE-2022-2833
Blender General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Endless Infinite loop in Blender-thumnailing due to logical bugs.

CVE-2022-28329
SCALANCE W1788-1 M12 General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 1 PoC

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed TCP packets received over the RemoteCapture feature. This could allow an attacker to lead to a denial of service condition which only affects the port used by the RemoteCapture feature.

CVE-2022-20004
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-179699767

CVE-2022-28986
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2022 1 PoC

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.

CVE-2022-29854
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 3 PoCs

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVE-2022-29866
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

CVE-2022-41169
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-29023
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A buffer overflow vulnerability exists in the razermouse driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of Service (DoS) and possibly escalate their privileges via a crafted buffer sent to the matrix_custom_frame device.

CVE-2022-30105
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2022 1 PoC

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.

CVE-2022-3182
Remote Desktop Manager General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-284 1 PoC

Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.

CVE-2022-29301
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.