3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-37027
Software Genérico General
7.2
HIGH
EPSS
6.2%
2022 1 PoC

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

CVE-2022-41001
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null)' command template.

CVE-2022-41002
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null)' command template.

CVE-2022-32282
AVideo General
7.2
HIGH
EPSS
0.5%
2022 CWE-836 1 PoC

An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.

CVE-2022-40986
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the '(ddns1|ddns2) mx WORD' command template.

CVE-2022-1032
crater-invoice/crater General
7.2
HIGH
EPSS
0.4%
2022 CWE-502 1 PoC

Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

CVE-2022-1106
mruby/mruby General
7.2
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

CVE-2022-1681
requarks/wiki General
7.2
HIGH
EPSS
0.3%
2022 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

CVE-2022-46568
Software Genérico General
7.2
HIGH
EPSS
2.0%
2022 5 PoCs

D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module.

CVE-2022-40999
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'gre index <1-8> tunnel A.B.C.D source (A.B.C.D|null) dest A.B.C.D keepalive (on|off) interval (<0-255>|null) retry (<0-255>|null) description (WORD|null)' command template.

CVE-2022-40994
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no firmwall keyword WORD description (WORD|null)' command template.

CVE-2022-40992
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no firmwall domain WORD description (WORD|null)' command template.

CVE-2022-27925
🔥 KEV Software Genérico General
7.2
HIGH
EPSS
94.3%
2022 16 PoCs

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVE-2022-23155
Wyse Management Suite General
7.2
HIGH
EPSS
0.7%
2022 CWE-434 1 PoC

Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.

CVE-2022-42946
Autodesk Maya General
7.1
HIGH
EPSS
0.1%
2022 1 PoC

Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-0139
radareorg/radare2 General
7.1
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-0588
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-862 1 PoC

Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-43941
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.4%
2022 CWE-611 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

CVE-2022-4504
openemr/openemr General
7.1
HIGH
EPSS
0.4%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.