3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-36620
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

CVE-2022-28991
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

CVE-2022-24346
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

CVE-2022-35069
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e.

CVE-2022-24237
Software Genérico General
N/A
UNKNOWN
EPSS
23.4%
2022 1 PoC

The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.

CVE-2022-48064
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

CVE-2022-32173
OrchardCore General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.

CVE-2022-0530
unzip General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

CVE-2022-26629
Software Genérico General
N/A
UNKNOWN
EPSS
30.5%
2022 2 PoCs

An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

CVE-2022-36663
Software Genérico General
N/A
UNKNOWN
EPSS
16.4%
2022 1 PoC

Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.

CVE-2022-30783
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVE-2022-34906
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

CVE-2022-39983
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

CVE-2022-31324
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.

CVE-2022-28104
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.

CVE-2022-1970
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-45063
Software Genérico General
N/A
UNKNOWN
EPSS
17.9%
2022 4 PoCs

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVE-2022-24958
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

CVE-2022-20133
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-206807679

CVE-2022-41198
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.