5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0630
mruby/mruby General
7.1
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-50950
Webile General
7.1
HIGH
EPSS
1.3%
2022 CWE-22 1 PoC

Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attackers can exploit path manipulation to access sensitive system directories and potentially compromise the mobile device's local file system.

CVE-2022-39880
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

CVE-2022-4105
kiwitcms/kiwi Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.

CVE-2022-42280
NVIDIA DGX servers General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

CVE-2022-21544
FLEXCUBE Universal Banking Web Database
7.1
HIGH
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availabi

CVE-2022-0087
keystonejs/keystone Web ⚡ nuclei
7.1
HIGH
EPSS
56.1%
2022 CWE-79 1 PoC

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-21593
HTTP Server Web Database
7.1
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data as well as unauthorized update, insert or delete access to

CVE-2022-25760
accesslog Web
7.1
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible for an attacker to execute arbitrary JavaScript code on the host that this package is being run on.

CVE-2022-0821
orchardcms/orchardcore Web
7.1
HIGH
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVE-2022-2924
yetiforcecompany/yetiforcecrm Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

CVE-2022-42946
Autodesk Maya General
7.1
HIGH
EPSS
0.1%
2022 1 PoC

Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-2995
cri-o DevOps
7.1
HIGH
EPSS
0.0%
2022 CWE-284 1 PoC

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

CVE-2022-0588
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-862 1 PoC

Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-43941
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.4%
2022 CWE-611 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

CVE-2022-1201
mruby/mruby General
7.1
HIGH
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.

CVE-2022-1451
radareorg/radare2 Web
7.1
HIGH
EPSS
0.3%
2022 CWE-788 2 PoCs

Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

CVE-2022-35880
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `NewInternalClient` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-25989
Eufy Homebase 2 General
7.1
HIGH
EPSS
0.1%
2022 CWE-290 1 PoC

An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.

CVE-2022-35822
Windows 10 Version 1809 Windows
7.1
HIGH
EPSS
0.8%
2022 1 PoC

Windows Defender Credential Guard Security Feature Bypass Vulnerability