3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-25298
sprinfall/webcc General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files from the server.

CVE-2022-42124
Software Genérico General
7.5
HIGH
EPSS
1.2%
2022 2 PoCs

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.

CVE-2022-32487
CPG BIOS General
7.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-3371
ikus060/rdiffweb General
7.5
HIGH
EPSS
0.5%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

CVE-2022-41999
OpenImageIO General
7.5
HIGH
EPSS
0.3%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-27924
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2022 0 PoCs

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

CVE-2022-24278
convert-svg-core General
7.5
HIGH
EPSS
0.7%
2022 1 PoC

The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

CVE-2022-47717
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).

CVE-2022-26387
Firefox General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVE-2022-44167
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.

CVE-2022-22288
Galaxy Store General
7.5
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.

CVE-2022-40303
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 5 PoCs

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.

CVE-2022-27673
AMD Link Android General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.

CVE-2022-36537
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.9%
2022 4 PoCs

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CVE-2022-25908
create-choo-electron General
7.4
HIGH
EPSS
1.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-47630
Software Genérico General
7.4
HIGH
EPSS
0.6%
2022 1 PoC

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

CVE-2022-25171
p4 General
7.4
HIGH
EPSS
1.9%
2022 1 PoC

The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

CVE-2022-1809
radareorg/radare2 General
7.4
HIGH
EPSS
0.3%
2022 CWE-824 1 PoC

Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2022-25916
mt7688-wiscan General
7.4
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

CVE-2022-25350
puppet-facter General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.