3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-25350
puppet-facter General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

CVE-2022-24377
cycle-import-check General
7.4
HIGH
EPSS
1.4%
2022 1 PoC

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

CVE-2022-26073
Eufy Homebase 2 General
7.4
HIGH
EPSS
0.1%
2022 CWE-190 1 PoC

A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.

CVE-2022-39299
passport-saml General
7.4
HIGH
EPSS
4.6%
2022 CWE-347 8 PoCs

Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to passport-saml version 3.2.2 or newer. The issue was also present in the beta releases of `node-saml` before

CVE-2022-25855
create-choo-app3 General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-1155
snipe/snipe-it General
7.4
HIGH
EPSS
0.3%
2022 CWE-840 1 PoC

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

CVE-2022-21191
global-modules-path General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

CVE-2022-26092
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

CVE-2022-24431
abacus-ext-cmdline General
7.4
HIGH
EPSS
1.9%
2022 1 PoC

All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.

CVE-2022-37193
Software Genérico General
7.4
HIGH
EPSS
0.3%
2022 1 PoC

Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials.

CVE-2022-0129
McAfee TechCheck General
7.4
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.

CVE-2022-25926
window-control General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

CVE-2022-25890
wifey General
7.4
HIGH
EPSS
1.5%
2022 CWE-78 1 PoC

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

CVE-2022-26964
Software Genérico General
7.4
HIGH
EPSS
0.3%
2022 1 PoC

Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.

CVE-2022-29217
pyjwt General
7.4
HIGH
EPSS
0.4%
2022 CWE-327 1 PoC

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always

CVE-2022-24860
databasir General
7.4
HIGH
EPSS
0.3%
2022 CWE-321 1 PoC

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at different IP addresses.

CVE-2022-48196
Software Genérico General
7.4
HIGH
EPSS
1.2%
2022 2 PoCs

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152, R7000 before 1.0.11.136, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

CVE-2022-25853
semver-tags General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.

CVE-2022-25923
exec-local-bin General
7.4
HIGH
EPSS
1.6%
2022 CWE-78 1 PoC

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.