3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-43941
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.4%
2022 CWE-611 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

CVE-2022-2134
inventree/inventree General
7.1
HIGH
EPSS
0.3%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

CVE-2022-4504
openemr/openemr General
7.1
HIGH
EPSS
0.4%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-35879
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `controlURL` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-1201
mruby/mruby General
7.1
HIGH
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.

CVE-2022-0139
radareorg/radare2 General
7.1
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-23400
ImageGear General
7.1
HIGH
EPSS
0.3%
2022 CWE-193 1 PoC

A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to denial of service or, depending on the application, to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2653
plankanban/planka General
7.1
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able to read any file in the system.

CVE-2022-35953
bookwyrm General
7.1
HIGH
EPSS
0.3%
2022 CWE-601 1 PoC

BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to read next. Some links in BookWyrm may be vulnerable to tabnabbing, a form of phishing that gives attackers an opportunity to redirect a user to a malicious site. The issue was patched in version 0.4.5.

CVE-2022-0144
shelljs/shelljs General
7.1
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

shelljs is vulnerable to Improper Privilege Management

CVE-2022-34388
SupportAssist General
7.1
HIGH
EPSS
0.1%
2022 CWE-318 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.

CVE-2022-35880
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `NewInternalClient` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-25989
Eufy Homebase 2 General
7.1
HIGH
EPSS
0.1%
2022 CWE-290 1 PoC

An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.

CVE-2022-31250
Tumbleweed General
7.1
HIGH
EPSS
0.1%
2022 CWE-59 1 PoC

A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.

CVE-2022-28754
Zoom On-Premise Meeting Connector MMR General
7.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-0128
vim/vim General
7.1
HIGH
EPSS
0.3%
2022 CWE-125 1 PoC

vim is vulnerable to Out-of-bounds Read

CVE-2022-0587
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-29458
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 3 PoCs

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

CVE-2022-28753
Zoom On-Premise Meeting Connector MMR General
7.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-39909
Samsung Gear IconX PC Manager General
7.1
HIGH
EPSS
0.0%
2022 CWE-345 1 PoC

Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.