3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-22542
SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer) General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-200 1 PoC

S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for Customer, Supplier and Business Partner objects exposes the private address fields of Employee Business Partners, to an actor that is not explicitly authorized to have access to that information, which could compromise Confidentiality.

CVE-2022-34913
Software Genérico General
N/A
UNKNOWN
EPSS
10.3%
2022 1 PoC

md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input

CVE-2022-22956
VMware Workspace ONE Access General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.9%
2022 2 PoCs

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

CVE-2022-22701
PartKeepr General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

CVE-2022-24655
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.

CVE-2022-35018
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVE-2022-29623
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.

CVE-2022-26507
Software Genérico General
N/A
UNKNOWN
EPSS
6.7%
2022 2 PoCs

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-39815
Software Genérico General
N/A
UNKNOWN
EPSS
13.5%
2022 1 PoC

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

CVE-2022-36115
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the CreateProcessAutosave() method to inject their own functionality into a development process. If (upon a warning) a user decides to recover unsaved work by using the last saved version, the malicious code could enter the workflow. Should the process action stages not be fully review

CVE-2022-0216
QEMU General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.

CVE-2022-22844
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

CVE-2022-26364
xen General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, Xen's safety logic doesn't account for CPU-induced cache non-coherency; cases where the CPU can cause the content of the cache to be different to

CVE-2022-26562
Software Genérico General
N/A
UNKNOWN
EPSS
2.7%
2022 1 PoC

An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).

CVE-2022-26239
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

CVE-2022-32296
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

CVE-2022-23079
motor-admin General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-116 1 PoC

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

CVE-2022-24345
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

CVE-2022-29469
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.