3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-43713
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data input because form validation could be bypassed.

CVE-2022-27468
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

CVE-2022-36117
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is configured to be accessible by a machine or the runtime resource security group, using further reverse engineering, an attacker can spoof a known machine and request known encrypted credentials to decrypt later.

CVE-2022-41167
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-27288
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

CVE-2022-30778
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-0725
keepass General
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-200 1 PoC

A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

CVE-2022-20224
Android General
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220732646

CVE-2022-24343
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

CVE-2022-27228
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2022 1 PoC

In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

CVE-2022-33108
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 3 PoCs

XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.

CVE-2022-24575
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.

CVE-2022-26105
SAP NetWeaver Enterprise Portal General
N/A
UNKNOWN
EPSS
1.5%
2022 CWE-79 1 PoC

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2022-39013
SAP BusinessObjects Business Intelligence Platform (Program Objects) General
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-200 1 PoC

Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.

CVE-2022-47696
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.

CVE-2022-32561
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.

CVE-2022-35019
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVE-2022-30852
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).

CVE-2022-31664
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-20413
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634