5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36773
Cognos Analytics General
7.1
HIGH
EPSS
1.0%
2022 1 PoC

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.

CVE-2022-35881
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `errorCode` and `errorDescription` XML tags, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-0938
star7th/showdoc Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-32505
Software Genérico General
7.1
HIGH
EPSS
0.1%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

CVE-2022-28184
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.

CVE-2022-32510
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-45836
Download Manager Web ⚡ nuclei
7.1
HIGH
EPSS
8.0%
2022 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

CVE-2022-35879
iota All-In-One Security Kit General
7.1
HIGH
EPSS
0.1%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `controlURL` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

CVE-2022-0144
shelljs/shelljs General
7.1
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

shelljs is vulnerable to Improper Privilege Management

CVE-2022-34292
Software Genérico DevOps Web Windows
7.1
HIGH
EPSS
0.0%
2022 1 PoC

Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647.

CVE-2022-0128
vim/vim General
7.1
HIGH
EPSS
0.3%
2022 CWE-125 1 PoC

vim is vulnerable to Out-of-bounds Read

CVE-2022-28754
Zoom On-Premise Meeting Connector MMR General
7.1
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-30579
TIBCO Spotfire Analytics Platform for AWS Marketplace Cloud
7.1
HIGH
EPSS
0.2%
2022 1 PoC

The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.

CVE-2022-2756
kareadita/kavita General ⚡ nuclei
7.1
HIGH
EPSS
56.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.

CVE-2022-46689
macOS General
7.0
HIGH
EPSS
85.6%
2022 8 PoCs

A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-41668
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-704 1 PoC

A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-41741
NGINX Web
7.0
HIGH
EPSS
0.8%
2022 CWE-787 1 PoC

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger proces

CVE-2022-42267
NVIDIA GPU Display Driver for Windows Windows
7.0
HIGH
EPSS
0.1%
2022 CWE-345 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-41222
Software Genérico General
7.0
HIGH
EPSS
0.0%
2022 3 PoCs

mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

CVE-2022-31144
redis Database
7.0
HIGH
EPSS
21.2%
2022 CWE-122 1 PoC

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.