3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-32760
iota All-In-One Security Kit General
8.6
HIGH
EPSS
0.5%
2022 CWE-489 1 PoC

A denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-0768
rudloff/alltube General
8.6
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

CVE-2022-22774
TIBCO Managed File Transfer Command Center General
8.6
HIGH
EPSS
0.7%
2022 1 PoC

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.

CVE-2022-4686
usememos/memos General
8.6
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-43939
🔥 KEV Pentaho Business Analytics Server General ⚡ nuclei
8.6
HIGH
EPSS
93.3%
2022 CWE-647 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CVE-2022-41412
Software Genérico General ⚡ nuclei
8.6
HIGH
EPSS
89.4%
2022 2 PoCs

An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.

CVE-2022-41985
uC-FTPs General
8.6
HIGH
EPSS
0.1%
2022 CWE-303 1 PoC

An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

CVE-2022-2713
cockpit-hq/cockpit General
8.6
HIGH
EPSS
1.1%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

CVE-2022-31188
cvat General
8.6
HIGH
EPSS
35.7%
2022 CWE-918 2 PoCs

CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-23425
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

CVE-2022-4812
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4800
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-940 1 PoC

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4798
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-50902
Wondershare FamiSafe General
8.5
HIGH
EPSS
0.0%
2022 CWE-91 1 PoC

Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\FamiSafe\ to inject malicious code that would run with LocalSystem permissions during service startup.

CVE-2022-50933
Cain & Abel General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2022-30713
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-30710
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-50914
EaseUS Data Recovery General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.

CVE-2022-50929
Connectify Hotspot General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Connectify\ConnectifyService.exe' to inject malicious executables and escalate privileges.

CVE-2022-50808
Cooler Master MasterPlus General
8.5
HIGH
EPSS
0.0%
2022 CWE-427 1 PoC

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.