3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-45640
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

CVE-2022-43140
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
40.0%
2022 0 PoCs

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.

CVE-2022-47076
Software Genérico General
7.5
HIGH
EPSS
23.4%
2022 3 PoCs

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.

CVE-2022-0281
microweber/microweber General ⚡ nuclei
7.5
HIGH
EPSS
18.6%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-40946
Software Genérico General
7.5
HIGH
EPSS
5.4%
2022 2 PoCs

On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.

CVE-2022-45635
Software Genérico General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.

CVE-2022-45059
Software Genérico General
7.5
HIGH
EPSS
1.5%
2022 1 PoC

An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.

CVE-2022-25904
safe-eval General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype.

CVE-2022-1713
jgraph/drawio General ⚡ nuclei
7.5
HIGH
EPSS
90.2%
2022 CWE-918 1 PoC

SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

CVE-2022-2321
heroiclabs/nakama General
7.5
HIGH
EPSS
0.3%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

CVE-2022-1722
jgraph/drawio General
7.5
HIGH
EPSS
0.2%
2022 CWE-918 1 PoC

SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses

CVE-2022-36319
Firefox ESR General
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

CVE-2022-25302
ASNeG/OpcUaStack General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed casting when unvalidated data is forwarded to boost::get function in OpcUaNodeIdBase.h. Exploiting this vulnerability is possible when sending a specifically crafted OPC UA message with a special encoded NodeId.

CVE-2022-2192
HYPR Server General
7.5
HIGH
EPSS
0.7%
2022 CWE-425 1 PoC

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

CVE-2022-25314
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

CVE-2022-39812
Software Genérico General
7.5
HIGH
EPSS
1.2%
2022 1 PoC

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary directory. Because the application does not check in which directory a file will be uploaded, an attacker can perform a variety of attacks that can result in unauthorized access to the server.

CVE-2022-48164
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
87.1%
2022 1 PoC

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2022-47116
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.

CVE-2022-47768
Software Genérico General
7.5
HIGH
EPSS
0.7%
2022 1 PoC

Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.

CVE-2022-25891
github.com/containrrr/shoutrrr/pkg/util General
7.5
HIGH
EPSS
0.6%
2022 1 PoC

The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.