3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-24008
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the confcli binary.

CVE-2022-24016
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the mesh_status_check binary.

CVE-2022-24020
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the network_check binary.

CVE-2022-30584
Software Genérico General
9.6
CRITICAL
EPSS
0.5%
2022 1 PoC

Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVE-2022-40083
Software Genérico General ⚡ nuclei
9.6
CRITICAL
EPSS
58.8%
2022 0 PoCs

Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

CVE-2022-24015
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the log_upload binary.

CVE-2022-27178
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.4%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_wan_cfg functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-24017
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the miniupnpd binary.

CVE-2022-24028
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the libcommonprod.so binary.

CVE-2022-2014
jgraph/drawio General
9.6
CRITICAL
EPSS
0.3%
2022 CWE-94 1 PoC

Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.

CVE-2022-24021
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the online_process binary.

CVE-2022-24018
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the multiWAN binary.

CVE-2022-0688
microweber/microweber General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-2216
ionicabizau/parse-url General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

CVE-2022-3224
ionicabizau/parse-url General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-115 1 PoC

Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.

CVE-2022-3993
kareadita/kavita General
9.4
CRITICAL
EPSS
1.4%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-3945
kareadita/kavita General
9.4
CRITICAL
EPSS
1.0%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-46164
NodeBB General
9.4
CRITICAL
EPSS
56.8%
2022 CWE-665 1 PoC

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

CVE-2022-0660
microweber/microweber General ⚡ nuclei
9.4
CRITICAL
EPSS
7.5%
2022 CWE-209 1 PoC

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0401
yuda-lyu/w-zip General
9.4
CRITICAL
EPSS
0.7%
2022 CWE-22 1 PoC

Path Traversal in NPM w-zip prior to 1.0.12.