3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-37139
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

CVE-2022-29326
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

CVE-2022-32192
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

CVE-2022-41852
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

Sin descripción disponible.

CVE-2022-25106
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2022-32868
iOS General
N/A
UNKNOWN
EPSS
0.6%
2022 3 PoCs

A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.

CVE-2022-48334
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow.

CVE-2022-26249
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.

CVE-2022-31782
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

CVE-2022-33887
utodesk® AutoCAD®, Advance Steel and Civil 3D® General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.

CVE-2022-33992
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

CVE-2022-28774
SAP Host Agent General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-863 1 PoC

Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

CVE-2022-25061
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2022 1 PoC

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

CVE-2022-1508
Kernel General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-125 1 PoC

An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.

CVE-2022-32271
Software Genérico General
N/A
UNKNOWN
EPSS
2.7%
2022 1 PoC

In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.

CVE-2022-25368
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

CVE-2022-23346
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

CVE-2022-25260
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).