5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-35290
SAP Authenticator for Android General
7.5
HIGH
EPSS
0.3%
2022 CWE-200 2 PoCs

Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

CVE-2022-1176
livehelperchat/livehelperchat General
7.5
HIGH
EPSS
0.3%
2022 CWE-843 1 PoC

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

CVE-2022-27674
AMD μProf Windows
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.

CVE-2022-21159
libiec61850 General
7.5
HIGH
EPSS
0.4%
2022 CWE-835 2 PoCs

A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence of malformed iec61850 messages to trigger this vulnerability.

CVE-2022-42060
Software Genérico Networking
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-3754
thorsten/phpmyfaq Web
7.5
HIGH
EPSS
0.9%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE-2022-25324
bignum General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.

CVE-2022-3602
OpenSSL General
7.5
HIGH
EPSS
83.5%
2022 7 PoCs

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms impl

CVE-2022-22143
convict Web
7.5
HIGH
EPSS
1.7%
2022 2 PoCs

The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)

CVE-2022-20347
Android General
7.5
HIGH
EPSS
0.7%
2022 2 PoCs

In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228450811

CVE-2022-3382
HIWIN Robot System Software General
7.5
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the controller and cause a denial-of-service condition.

CVE-2022-39801
SAP GRC Access Control Emergency Access Management Networking
7.5
HIGH
EPSS
0.4%
2022 CWE-287 1 PoC

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.

CVE-2022-24434
dicer General
7.5
HIGH
EPSS
2.0%
2022 3 PoCs

This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

CVE-2022-21421
Business Intelligence Enterprise Edition Web Database
7.5
HIGH
EPSS
4.8%
2022 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Conf

CVE-2022-31626
PHP Web Database
7.5
HIGH
EPSS
10.2%
2022 CWE-120 1 PoC

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVE-2022-27782
https://github.com/curl/curl Web Networking
7.5
HIGH
EPSS
0.5%
2022 CWE-840 1 PoC

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

CVE-2022-31129
moment Web
7.5
HIGH
EPSS
3.4%
2022 CWE-400 1 PoC

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can b

CVE-2022-25848
static-dev-server General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.

CVE-2022-29831
GX Works3 Cloud
7.5
HIGH
EPSS
1.2%
2022 CWE-259 1 PoC

Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.

CVE-2022-4140
Welcart e-Commerce Web Windows ⚡ nuclei
7.5
HIGH
EPSS
54.3%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server