3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2321
heroiclabs/nakama General
7.5
HIGH
EPSS
0.3%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

CVE-2022-1579
Login Block IPs General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

CVE-2022-1722
jgraph/drawio General
7.5
HIGH
EPSS
0.2%
2022 CWE-918 1 PoC

SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses

CVE-2022-42893
syngo Dynamics General
7.5
HIGH
EPSS
0.2%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.

CVE-2022-2192
HYPR Server General
7.5
HIGH
EPSS
0.7%
2022 CWE-425 1 PoC

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

CVE-2022-45269
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
27.4%
2022 0 PoCs

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

CVE-2022-25027
Software Genérico General
7.5
HIGH
EPSS
1.3%
2022 1 PoC

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

CVE-2022-48164
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
87.1%
2022 1 PoC

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2022-1723
jgraph/drawio General
7.5
HIGH
EPSS
0.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

CVE-2022-36319
Firefox ESR General
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

CVE-2022-44156
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.

CVE-2022-40946
Software Genérico General
7.5
HIGH
EPSS
5.4%
2022 2 PoCs

On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.

CVE-2022-24278
convert-svg-core General
7.5
HIGH
EPSS
0.7%
2022 1 PoC

The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

CVE-2022-34393
BIOS General
7.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-26077
OAS Platform General
7.5
HIGH
EPSS
0.2%
2022 CWE-319 1 PoC

A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing attack can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2022-22549
PowerScale OneFS General
7.5
HIGH
EPSS
0.4%
2022 CWE-295 1 PoC

Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials.

CVE-2022-24375
node-opcua General
7.5
HIGH
EPSS
0.6%
2022 1 PoC

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-47116
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.

CVE-2022-3371
ikus060/rdiffweb General
7.5
HIGH
EPSS
0.5%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

CVE-2022-43343
Software Genérico General
7.5
HIGH
EPSS
4.1%
2022 1 PoC

N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c.