5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3786
OpenSSL General
7.5
HIGH
EPSS
27.3%
2022 3 PoCs

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In

CVE-2022-22110
DaybydayCRM General
7.5
HIGH
EPSS
0.3%
2022 CWE-521 1 PoC

In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.

CVE-2022-24716
icingaweb2 General ⚡ nuclei
7.5
HIGH
EPSS
93.1%
2022 CWE-22 7 PoCs

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

CVE-2022-0281
microweber/microweber General ⚡ nuclei
7.5
HIGH
EPSS
18.6%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-25027
Software Genérico General
7.5
HIGH
EPSS
1.3%
2022 1 PoC

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

CVE-2022-21466
Commerce Guided Search / Oracle Commerce Experience Manager Web Database
7.5
HIGH
EPSS
1.7%
2022 1 PoC

Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-3780
Remote Desktop Manager Database
7.5
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions.

CVE-2022-40874
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.

CVE-2022-45269
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
27.4%
2022 0 PoCs

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

CVE-2022-1579
Login Block IPs General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

CVE-2022-30746
Smart Things Web
7.5
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

CVE-2022-42953
Software Genérico General
7.5
HIGH
EPSS
10.9%
2022 2 PoCs

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

CVE-2022-3691
DeepL Pro API translation plugin Web Windows
7.5
HIGH
EPSS
1.1%
2022 1 PoC

The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.

CVE-2022-34126
Software Genérico Web
7.5
HIGH
EPSS
1.6%
2022 1 PoC

The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.

CVE-2022-25851
jpeg-js General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.

CVE-2022-25891
github.com/containrrr/shoutrrr/pkg/util General
7.5
HIGH
EPSS
0.6%
2022 1 PoC

The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.

CVE-2022-46076
Software Genérico Web
7.5
HIGH
EPSS
1.3%
2022 1 PoC

D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.

CVE-2022-21192
serve-lite General
7.5
HIGH
EPSS
1.4%
2022 CWE-22 1 PoC

All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().

CVE-2022-38873
Software Genérico General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta and earlier, DAP-3662 v1.05rc047 and earlier allows attackers to cause a Denial of Service (DoS) via uploading a crafted firmware after modifying the firmware header.

CVE-2022-4621
Sanyo CCTV Network Camera Web
7.5
HIGH
EPSS
0.1%
2022 CWE-352 1 PoC

Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allow an attacker to perform changes with administrator level privileges.