3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-30264
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

CVE-2022-29587
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.

CVE-2022-31665
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
3.1%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVE-2022-31322
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.

CVE-2022-29856
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 3 PoCs

A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.

CVE-2022-23178
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2022 1 PoC

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

CVE-2022-43703
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-427 1 PoC

An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.

CVE-2022-35582
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not disclosed in the documentation. Knowing the credentials, attackers can use this feature to gain uncontrolled access to the device and therefore are considered an undocumented possibility for remote control.

CVE-2022-26966
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.

CVE-2022-20142
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-216631962

CVE-2022-41724
crypto/tls General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).

CVE-2022-27295
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVE-2022-3857
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-27904
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.

CVE-2022-25331
Trend Micro ServerProtect for Storage General
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process.

CVE-2022-22834
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2022 1 PoC

An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.

CVE-2022-50798
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

Sin descripción disponible.

CVE-2022-32241
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 1 PoC

When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-33885
utodesk® AutoCAD®, Advance Steel and Civil 3D® General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.

CVE-2022-34556
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.