3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-22540
SAP NetWeaver AS ABAP (Workplace Server) General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-89 1 PoC

SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.

CVE-2022-30286
Software Genérico General
N/A
UNKNOWN
EPSS
30.8%
2022 3 PoCs

pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.

CVE-2022-30274
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly, the ACE1000 RTU can route MDLC traffic over Extended Command and Management Protocol (XCMP) and Network Layer (XNL) networks via the MDLC driver. Authentication to the XNL port is protected by TEA in ECB mode using a hardcoded key.

CVE-2022-33886
Autodesk Maya General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.

CVE-2022-25060
Software Genérico General
N/A
UNKNOWN
EPSS
74.7%
2022 1 PoC

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

CVE-2022-40476
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.

CVE-2022-30295
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.

CVE-2022-40715
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

CVE-2022-28365
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.2%
2022 2 PoCs

Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.

CVE-2022-24576
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

GPAC 1.0.1 is affected by Use After Free through MP4Box.

CVE-2022-1716
Keep My Notes General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

CVE-2022-31660
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
3.4%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-36123
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.

CVE-2022-34008
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.

CVE-2022-30317
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experion LX Control Data Access (CDA) EpicMo protocol with unauthenticated functionality issue. The affected components are characterized as: Honeywell Control Data Access (CDA) EpicMo (55565/TCP). The potential impact is: Firmware manipulation, Denial of service. The Honeywell Experion LX Distributed Control System (DCS) utilizes the Control Data Access (CDA) EpicMo protocol (55565/TCP) for device diagnostics and maintenance purposes. This protocol doe

CVE-2022-46485
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2022 2 PoCs

Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".

CVE-2022-24334
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

CVE-2022-26643
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.

CVE-2022-34578
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.