3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-31362
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-32270
Software Genérico General
N/A
UNKNOWN
EPSS
4.1%
2022 1 PoC

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).

CVE-2022-41181
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-28896
Software Genérico General
N/A
UNKNOWN
EPSS
33.4%
2022 1 PoC

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-28328
SCALANCE W1788-1 M12 General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed Multicast LLC frames. This could allow an attacker to trigger a denial of service condition.

CVE-2022-37060
Software Genérico General
N/A
UNKNOWN
EPSS
39.5%
2022 2 PoCs

FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

CVE-2022-38349
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

CVE-2022-28383
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 14 PoCs

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

CVE-2022-32272
Software Genérico General
N/A
UNKNOWN
EPSS
21.2%
2022 2 PoCs

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

CVE-2022-41174
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-35619
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2022 1 PoC

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.

CVE-2022-32237
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 1 PoC

When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-40140
Trend Micro Apex One General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVE-2022-24253
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

CVE-2022-32441
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from Faulting Address controls subsequent Write Address starting at msvcrt!memcpy+0x0000000000000056.

CVE-2022-29539
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2022 1 PoC

resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\ commands) and inject arbitrary system commands with the privileges of the application user.

CVE-2022-2007
Chrome General
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-0995
kernel General
N/A
UNKNOWN
EPSS
17.0%
2022 CWE-787 8 PoCs

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

CVE-2022-26952
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.

CVE-2022-34494
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.