3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-40896
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

CVE-2022-26482
Software Genérico General
N/A
UNKNOWN
EPSS
23.6%
2022 1 PoC

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.

CVE-2022-48560
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVE-2022-29320
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-29328
Software Genérico General
N/A
UNKNOWN
EPSS
2.6%
2022 1 PoC

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.

CVE-2022-30552
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Das U-Boot 2022.01 has a Buffer Overflow.

CVE-2022-24975
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

CVE-2022-31590
SAP PowerDesigner Proxy 16.7 General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-428 1 PoC

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.

CVE-2022-27294
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVE-2022-27286
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

CVE-2022-24955
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

CVE-2022-30858
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0

CVE-2022-1671
Kernel General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-476 1 PoC

A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.

CVE-2022-26646
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.

CVE-2022-35620
Software Genérico General
N/A
UNKNOWN
EPSS
25.2%
2022 1 PoC

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

CVE-2022-23102
SINEMA Remote Connect Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2022 CWE-601 2 PoCs

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.

CVE-2022-39821
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.

CVE-2022-28932
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

CVE-2022-33916
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.

CVE-2022-27261
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.