3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-24442
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

CVE-2022-24252
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2022 1 PoC

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

CVE-2022-36271
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2022 1 PoC

Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.

CVE-2022-22639
iOS and iPadOS General
N/A
UNKNOWN
EPSS
7.7%
2022 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

CVE-2022-26189
Software Genérico General
N/A
UNKNOWN
EPSS
19.4%
2022 1 PoC

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.

CVE-2022-1998
Kernel General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-416 1 PoC

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVE-2022-26269
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

Suzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages.

CVE-2022-41188
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-29858
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.

CVE-2022-23080
directus General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-918 1 PoC

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.

CVE-2022-31593
SAP Business One General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-74 1 PoC

SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

CVE-2022-2977
Linux kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate privileges on the system.

CVE-2022-30264
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

CVE-2022-29587
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.

CVE-2022-31665
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
3.1%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVE-2022-31322
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.

CVE-2022-29856
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 3 PoCs

A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.

CVE-2022-23178
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2022 1 PoC

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

CVE-2022-43703
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-427 1 PoC

An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.

CVE-2022-35582
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not disclosed in the documentation. Knowing the credentials, attackers can use this feature to gain uncontrolled access to the device and therefore are considered an undocumented possibility for remote control.