3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-40769
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 2 PoCs

profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.

CVE-2022-36118
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the SetProcessAttributes administrative function. Abusing this function will allow any Blue Prism user to publish, unpublish, or retire processes. Using this function, any logged-in user can change the status of a process, an action allowed only intended for users with the Edit Process permission.

CVE-2022-26243
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.

CVE-2022-35014
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Advancecomp v2.3 contains a segmentation fault.

CVE-2022-30239
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.

CVE-2022-32065
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.

CVE-2022-29354
Software Genérico General
N/A
UNKNOWN
EPSS
3.9%
2022 1 PoC

An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.

CVE-2022-30079
Software Genérico General
N/A
UNKNOWN
EPSS
11.0%
2022 2 PoCs

Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.

CVE-2022-38788
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

CVE-2022-1355
libtiff General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-121 1 PoC

A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.

CVE-2022-3656
Chrome General
N/A
UNKNOWN
EPSS
2.6%
2022 1 PoC

Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2022-24328
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.

CVE-2022-48165
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 0 PoCs

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2022-31598
SAP Business Objects General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-345 1 PoC

Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-1922
GStreamer General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-122 1 PoC

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However,

CVE-2022-31457
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

RTX TRAP v1.0 allows attackers to perform a directory traversal via a crafted request sent to the endpoint /data/.

CVE-2022-38557
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

CVE-2022-38779
kibana General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-601 1 PoC

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

CVE-2022-27658
SAP Innovation management General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-862 1 PoC

Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

CVE-2022-20135
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220303465