3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-47037
Software Genérico General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

CVE-2022-42125
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.

CVE-2022-23854
InTouch Access Anywhere General ⚡ nuclei
7.5
HIGH
EPSS
92.2%
2022 CWE-23 2 PoCs

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

CVE-2022-0203
crater-invoice/crater General
7.5
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

CVE-2022-24278
convert-svg-core General
7.5
HIGH
EPSS
0.7%
2022 1 PoC

The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

CVE-2022-1711
jgraph/drawio General ⚡ nuclei
7.5
HIGH
EPSS
35.4%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

CVE-2022-27924
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2022 0 PoCs

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

CVE-2022-21935
Metasys ADS/ADX/OAS server General
7.5
HIGH
EPSS
0.2%
2022 CWE-620 1 PoC

A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.

CVE-2022-47925
csaf-validator-service General
7.5
HIGH
EPSS
1.3%
2022 CWE-20 1 PoC

The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a partial DoS of the service. Only the request of the attacker is affected by this vulnerability.

CVE-2022-1784
jgraph/drawio General
7.5
HIGH
EPSS
0.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.

CVE-2022-28750
Zoom On-Premise Meeting Connector Zone Controller (ZC) General
7.5
HIGH
EPSS
0.6%
2022 CWE-121 1 PoC

Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this vulnerability could also be leveraged to execute arbitrary code.

CVE-2022-40898
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVE-2022-50978
VibroLine VLX1 HD 5.0 General
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

CVE-2022-25903
opcua General
7.5
HIGH
EPSS
0.6%
2022 1 PoC

The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, when it allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed.

CVE-2022-26026
OAS Platform General
7.5
HIGH
EPSS
0.4%
2022 CWE-306 1 PoC

A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this vulnerability.

CVE-2022-22781
Zoom Client for Meetings for MacOS (Standard and for IT Admin) General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

CVE-2022-37620
Software Genérico General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.

CVE-2022-39046
Software Genérico General
7.5
HIGH
EPSS
0.7%
2022 4 PoCs

An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.

CVE-2022-43326
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.

CVE-2022-25852
pg-native General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.