3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-29611
SAP NetWeaver Application Server for ABAP and ABAP Platform General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-862 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

CVE-2022-22845
Software Genérico General
N/A
UNKNOWN
EPSS
13.5%
2022 1 PoC

QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.

CVE-2022-40764
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

CVE-2022-37709
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to open a door and drive the car away by leveraging access to a legitimate Phone Key.

CVE-2022-30260
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.

CVE-2022-28805
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

CVE-2022-24562
Software Genérico General
N/A
UNKNOWN
EPSS
49.2%
2022 3 PoCs

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

CVE-2022-44215
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2022 1 PoC

There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

CVE-2022-35016
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Advancecomp v2.3 was discovered to contain a heap buffer overflow.

CVE-2022-22534
SAP NetWeaver (ABAP and Java application Servers) General
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

CVE-2022-24341
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

CVE-2022-29324
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2022 1 PoC

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

CVE-2022-35070
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x65fc97.

CVE-2022-29948
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 3 PoCs

Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass attack that enables an attacker to gain access to the stored encrypted data. Normally, the encrypted disk partition with this data is unlocked by entering the correct passcode (6 to 14 digits) via the keypad and pressing the Unlock button. This authentication is performed by an unknown microcontroller. By replacing this microcontroller on a target device with one from an attacker-controlled Lepin EP-KP001 whose passcode is known, it is possible to successfully unlock the target

CVE-2022-31589
SAP ERP, localization for CEE countries. General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-863 1 PoC

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

CVE-2022-36619
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.

CVE-2022-22805
SmartConnect General
N/A
UNKNOWN
EPSS
8.2%
2022 CWE-120 1 PoC

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=10

CVE-2022-28796
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

CVE-2022-29618
SAP NetWeaver Development Infrastructure (Design Time Repository) General
N/A
UNKNOWN
EPSS
3.1%
2022 CWE-79 1 PoC

Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-32193
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.