3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-29458
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 3 PoCs

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

CVE-2022-39909
Samsung Gear IconX PC Manager General
7.1
HIGH
EPSS
0.0%
2022 CWE-345 1 PoC

Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

CVE-2022-0630
mruby/mruby General
7.1
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-28753
Zoom On-Premise Meeting Connector MMR General
7.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-50950
Webile General
7.1
HIGH
EPSS
1.3%
2022 CWE-22 1 PoC

Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attackers can exploit path manipulation to access sensitive system directories and potentially compromise the mobile device's local file system.

CVE-2022-33926
Wyse Management Suite General
7.1
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.

CVE-2022-39880
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

CVE-2022-0580
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-863 1 PoC

Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-41221
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 1 PoC

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

CVE-2022-0755
salesagility/suitecrm General
7.1
HIGH
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

CVE-2022-0896
microweber/microweber General
7.1
HIGH
EPSS
1.0%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-32505
Software Genérico General
7.1
HIGH
EPSS
0.1%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

CVE-2022-42280
NVIDIA DGX servers General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

CVE-2022-50799
Fetch Softworks Fetch FTP Client General
7.1
HIGH
EPSS
0.1%
2022 CWE-770 2 PoCs

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application.

CVE-2022-2098
kromitgmbh/titra General
7.1
HIGH
EPSS
0.3%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.

CVE-2022-0436
gruntjs/grunt General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

CVE-2022-1886
vim/vim General
7.1
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-41670
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-41211
SAP 3D Visual Enterprise Author General
7.0
HIGH
EPSS
0.2%
2022 CWE-787 1 PoC

Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which refers to overwritten space in memory. The accessed memory must be filled with code to execute the attack. Therefore, repeated success is unlikely.Stack-based buffer overflow. Since the memory overwritten is random, based on access rights of the memory, repeated success is not assured.

CVE-2022-2564
automattic/mongoose General
7.0
HIGH
EPSS
2.9%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.