3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-41211
SAP 3D Visual Enterprise Author General
7.0
HIGH
EPSS
0.2%
2022 CWE-787 1 PoC

Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which refers to overwritten space in memory. The accessed memory must be filled with code to execute the attack. Therefore, repeated success is unlikely.Stack-based buffer overflow. Since the memory overwritten is random, based on access rights of the memory, repeated success is not assured.

CVE-2022-41670
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-41668
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-704 1 PoC

A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-2820
namelessmc/nameless General
7.0
HIGH
EPSS
0.3%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.

CVE-2022-3133
jgraph/drawio General
7.0
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.

CVE-2022-41667
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-46689
macOS General
7.0
HIGH
EPSS
85.6%
2022 8 PoCs

A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-41222
Software Genérico General
7.0
HIGH
EPSS
0.0%
2022 3 PoCs

mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

CVE-2022-41669
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.0%
2022 CWE-347 1 PoC

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-50682
Xperience General
6.9
MEDIUM
EPSS
0.1%
2022 CWE-93 1 PoC

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

CVE-2022-46361
OneWireless General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-77 1 PoC

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.

CVE-2022-25842
com.alibaba.oneagent:one-java-agent-plugin General
6.9
MEDIUM
EPSS
2.7%
2022 2 PoCs

All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.

CVE-2022-39908
Samsung Mobile Devices General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-367 1 PoC

TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVE-2022-50788
Impact/Pulse/First General
6.9
MEDIUM
EPSS
0.6%
2022 CWE-548 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.

CVE-2022-50692
Impact/Pulse/First General
6.9
MEDIUM
EPSS
0.1%
2022 CWE-613 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized access to the application.

CVE-2022-50686
Xperience General
6.9
MEDIUM
EPSS
0.1%
2022 CWE-209 1 PoC

An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.

CVE-2022-50687
Cobian Backup Gravity General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-120 1 PoC

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.

CVE-2022-1401
CMDB General
6.9
MEDIUM
EPSS
5.0%
2022 CWE-863 1 PoC

Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.

CVE-2022-50790
Impact/Pulse/First General
6.9
MEDIUM
EPSS
0.4%
2022 CWE-306 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication.

CVE-2022-50689
Cobian Reflector General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-120 1 PoC

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.