5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30150
Windows 10 Version 1809 Windows
7.5
HIGH
EPSS
2.3%
2022 1 PoC

Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability

CVE-2022-38840
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
58.1%
2022 1 PoC

cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.

CVE-2022-21371
WebLogic Server DevOps Web Database ⚡ nuclei
7.5
HIGH
EPSS
93.4%
2022 5 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVE-2022-24412
PowerScale OneFS General
7.5
HIGH
EPSS
0.5%
2022 CWE-229 1 PoC

Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.

CVE-2022-39412
Access Manager Web Database
7.5
HIGH
EPSS
4.3%
2022 1 PoC

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-23635
istio Web
7.5
HIGH
EPSS
0.7%
2022 CWE-287 1 PoC

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane crashing. This endpoint is served over TLS port 15012, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radius. However, for some deployments, especially [multicluster](https://istio.io/latest/docs/setup/inst

CVE-2022-21191
global-modules-path General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

CVE-2022-20866
Cisco Adaptive Security Appliance (ASA) Software Networking
7.4
HIGH
EPSS
8.9%
2022 CWE-203 1 PoC

A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. An attacker could exploit this vulnerability by using a Lenstra side-channel attack against the targeted device. A successful exploit could allow the attacker to retrieve the RSA private key. The following condit

CVE-2022-25890
wifey General
7.4
HIGH
EPSS
1.5%
2022 CWE-78 1 PoC

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

CVE-2022-1155
snipe/snipe-it General
7.4
HIGH
EPSS
0.3%
2022 CWE-840 1 PoC

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

CVE-2022-1467
AVEVA InTouch Access Anywhere Windows
7.4
HIGH
EPSS
0.3%
2022 CWE-668 1 PoC

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVE-2022-25916
mt7688-wiscan General
7.4
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

CVE-2022-23632
traefik Web Networking
7.4
HIGH
EPSS
0.6%
2022 CWE-295 1 PoC

Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a wrong TLS configuration. When sending a request using FQDN handled by a router configured with a dedicated TLS configuration, the TLS configuration falls back to the default configuration that might not correspond to the configured one. If the CNAME flattening is enabled, the sel

CVE-2022-24377
cycle-import-check General
7.4
HIGH
EPSS
1.4%
2022 1 PoC

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

CVE-2022-0749
SinGooCMS.Utility Web
7.4
HIGH
EPSS
0.5%
2022 1 PoC

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

CVE-2022-35919
minio Web Cloud
7.4
HIGH
EPSS
8.7%
2022 CWE-22 1 PoC

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.

CVE-2022-26092
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

CVE-2022-25906
is-http2 Web
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.

CVE-2022-25962
vagrant.js General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

CVE-2022-0432
mastodon/mastodon General ⚡ nuclei
7.4
HIGH
EPSS
57.1%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.