5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1021
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.3%
2022 CWE-922 1 PoC

Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.

CVE-2022-1649
radareorg/radare2 Web
7.6
HIGH
EPSS
0.2%
2022 CWE-476 2 PoCs

Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).

CVE-2022-0372
crater-invoice/crater Web
7.6
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.

CVE-2022-2472
CS-C6N-A0-1C2WFR General
7.6
HIGH
EPSS
0.2%
2022 CWE-665 1 PoC

Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428.

CVE-2022-0280
McAfee Total Protection for Windows Windows
7.5
HIGH
EPSS
0.2%
2022 CWE-367 1 PoC

A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted and potentially cause denial of service. This attack exploits the way symlinks are created and how the product works with them.

CVE-2022-45640
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

CVE-2022-37301
Modicon M340 CPU (part numbers BMXP34*) General
7.5
HIGH
EPSS
0.5%
2022 CWE-191 1 PoC

A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)

CVE-2022-24190
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a POST request to accept their own bind request, without the end-users approval or interaction.

CVE-2022-4794
AAWP Web Networking Windows
7.5
HIGH
EPSS
0.5%
2022 1 PoC

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

CVE-2022-4874
NF20 Networking
7.5
HIGH
EPSS
0.6%
2022 1 PoC

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.

CVE-2022-42277
NVIDIA DGX servers General
7.5
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-23990
Software Genérico General
7.5
HIGH
EPSS
3.7%
2022 3 PoCs

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVE-2022-44017
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local storage after logout.

CVE-2022-44016
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2022 1 PoC

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an '"ImagesPath":"C:\\"' value.

CVE-2022-2591
FLEX-1085 General
7.5
HIGH
EPSS
3.8%
2022 CWE-404 1 PoC

A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-4303
WP Limit Login Attempts Web Windows
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms.

CVE-2022-37017
Symantec Endpoint Protection Windows
7.5
HIGH
EPSS
8.0%
2022 1 PoC

Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

CVE-2022-25936
servst General
7.5
HIGH
EPSS
1.6%
2022 CWE-22 1 PoC

Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.

CVE-2022-1119
Simple File List Web Windows ⚡ nuclei
7.5
HIGH
EPSS
82.3%
2022 CWE-22 3 PoCs

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

CVE-2022-2192
HYPR Server General
7.5
HIGH
EPSS
0.7%
2022 CWE-425 1 PoC

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.