3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-28758
Zoom On-Premise Meeting Connector MMR General
8.2
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-33938
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.2%
2022 CWE-134 1 PoC

A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-32488
CPG BIOS General
8.2
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-35874
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `ssid` and `ssid_hex` configuration parameters, as used within the `testWifiAP` XCMD handler

CVE-2022-28759
Zoom On-Premise Meeting Connector MMR General
8.2
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-3389
ikus060/rdiffweb General
8.2
HIGH
EPSS
0.6%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

CVE-2022-25878
protobufjs General
8.2
HIGH
EPSS
0.4%
2022 2 PoCs

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

CVE-2022-1044
polonel/trudesk General
8.2
HIGH
EPSS
0.3%
2022 CWE-922 1 PoC

Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.

CVE-2022-0086
transloadit/uppy General
8.2
HIGH
EPSS
0.3%
2022 CWE-918 1 PoC

uppy is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2022-32489
CPG BIOS General
8.2
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-0871
gogs/gogs General
8.2
HIGH
EPSS
1.0%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2022-2313
Trellix Agent (TA) General
8.2
HIGH
EPSS
0.0%
2022 1 PoC

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

CVE-2022-1774
jgraph/drawio General
8.2
HIGH
EPSS
0.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

CVE-2022-25334
OMAP General
8.2
HIGH
EPSS
0.1%
2022 CWE-121 1 PoC

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, present in mask ROM. A module with a sufficiently large signature field causes a stack overflow, affecting secure kernel data pages. This can be leveraged to obtain arbitrary code execution in secure supervisor context by overwriting a SHA256 function pointer in the secure kernel data area when loading a forged, unsigned SK_LOAD module encrypted with the CEK (obtainable through CVE-2022-25332). This constitutes a full brea

CVE-2022-4807
usememos/memos General
8.2
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-35876
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` and `key` configuration parameters, as used within the `testWifiAP` XCMD handler

CVE-2022-38491
Software Genérico General
8.2
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.

CVE-2022-0991
admidio/admidio General
8.2
HIGH
EPSS
0.2%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.

CVE-2022-25333
OMAP General
8.2
HIGH
EPSS
0.0%
2022 CWE-347 1 PoC

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routine. However, only the module header authenticity is validated. An adversary can re-use any correctly signed header and append a forged payload, to be encrypted using the CEK (obtainable through CVE-2022-25332) in order to obtain arbitrary code execution in secure context. This constitutes a full break of the TEE security architecture.

CVE-2022-4806
usememos/memos General
8.2
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.