3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-42273
NVIDIA DGX servers General
8.1
HIGH
EPSS
0.6%
2022 CWE-120 1 PoC

NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVE-2022-21235
github.com/Masterminds/vcs General
8.1
HIGH
EPSS
0.5%
2022 1 PoC

The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVE-2022-4803
usememos/memos General
8.1
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1065
Abacus ERP General
8.1
HIGH
EPSS
1.7%
2022 CWE-304 1 PoC

A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 2022-01-15; v2020 versions prior to R6 of 2022-01-15; v2019 versions later than R5 (service pack); v2018 versions later than R5 (service pack). This issue does not affect: Abacus ERP v2019 versions prior to R5 of 2020-03-15; v2018 versions prior to R7 of 2020-04-15; v2017 version and prior versions and prior versions.

CVE-2022-26852
PowerScale OneFS General
8.1
HIGH
EPSS
1.4%
2022 CWE-337 1 PoC

Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise.

CVE-2022-44311
Software Genérico General
8.1
HIGH
EPSS
3.7%
2022 2 PoCs

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.

CVE-2022-4567
openemr/openemr General
8.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-43607
Open Babel General
8.1
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-43600
OpenImageIO General
8.1
HIGH
EPSS
0.8%
2022 CWE-122 1 PoC

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `xmax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT16`

CVE-2022-2027
kromitgmbh/titra General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVE-2022-0155
follow-redirects/follow-redirects General
8.0
HIGH
EPSS
1.3%
2022 CWE-359 1 PoC

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVE-2022-21668
pipenv General
8.0
HIGH
EPSS
1.5%
2022 CWE-20 1 PoC

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which will cause victims who use pipenv to install the requirements file to download dependencies from a package index server controlled by the attacker. By embedding malicious code in packages served from their malicious index server, the attacker can trigger arbitrary remote code execution (RCE) on the victims' systems. If a

CVE-2022-2486
WN535K2 General ⚡ nuclei
8.0
HIGH
EPSS
91.0%
2022 CWE-78 1 PoC

A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.

CVE-2022-22121
nocodb General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.

CVE-2022-21225
Intel(R) Data Center Manager software General
8.0
HIGH
EPSS
1.5%
2022 2 PoCs

Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-21934
Metasys ADS/ADX/OAS server General
8.0
HIGH
EPSS
0.3%
2022 CWE-620 1 PoC

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.

CVE-2022-1410
CMDB General
8.0
HIGH
EPSS
1.2%
2022 CWE-78 1 PoC

OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-2487
WN535K2 General ⚡ nuclei
8.0
HIGH
EPSS
93.1%
2022 CWE-78 1 PoC

A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.

CVE-2022-39882
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2022 CWE-787 1 PoC

Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.

CVE-2022-39852
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.