5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30584
Software Genérico General
9.6
CRITICAL
EPSS
0.5%
2022 1 PoC

Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVE-2022-36180
Software Genérico Web
9.6
CRITICAL
EPSS
0.2%
2022 1 PoC

Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.

CVE-2022-24027
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the libcommon.so binary.

CVE-2022-24015
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the log_upload binary.

CVE-2022-3741
chatwoot/chatwoot General
9.4
CRITICAL
EPSS
0.5%
2022 CWE-307 1 PoC

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.

CVE-2022-1592
clinical-genomics/scout Web
9.4
CRITICAL
EPSS
0.2%
2022 CWE-918 2 PoCs

Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...

CVE-2022-1682
neorazorx/facturascripts Web
9.4
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser

CVE-2022-0688
microweber/microweber General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0401
yuda-lyu/w-zip General
9.4
CRITICAL
EPSS
0.7%
2022 CWE-22 1 PoC

Path Traversal in NPM w-zip prior to 1.0.12.

CVE-2022-0942
star7th/showdoc Web
9.4
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-3224
ionicabizau/parse-url General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-115 1 PoC

Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.

CVE-2022-41271
NetWeaver Process Integration Web
9.4
CRITICAL
EPSS
0.8%
2022 CWE-862 1 PoC

An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users and data, leading to a considerable impact on confidentiality as well as availability and a limited impact on the integrity of the application. These operations can be used to: * Read any information * Modify sensitive information * Denial of Service attacks (DoS) * S

CVE-2022-46164
NodeBB General
9.4
CRITICAL
EPSS
56.8%
2022 CWE-665 1 PoC

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

CVE-2022-26833
OAS Platform Web ⚡ nuclei
9.4
CRITICAL
EPSS
92.1%
2022 CWE-306 1 PoC

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2022-3945
kareadita/kavita General
9.4
CRITICAL
EPSS
1.0%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-3993
kareadita/kavita General
9.4
CRITICAL
EPSS
1.4%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-0660
microweber/microweber General ⚡ nuclei
9.4
CRITICAL
EPSS
7.5%
2022 CWE-209 1 PoC

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-1782
erudika/para Web
9.4
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11.

CVE-2022-2216
ionicabizau/parse-url General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

CVE-2022-1212
mruby/mruby General
9.3
CRITICAL
EPSS
0.9%
2022 CWE-416 1 PoC

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.