2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-23818
3rd Gen AMD EPYC™ General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.

CVE-2022-36537
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.9%
2022 4 PoCs

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CVE-2022-41723
net/http Web
7.5
HIGH
EPSS
0.3%
2022 1 PoC

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVE-2022-25304
opcua General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-1119
Simple File List Web Windows ⚡ nuclei
7.5
HIGH
EPSS
82.3%
2022 CWE-22 3 PoCs

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

CVE-2022-3174
ikus060/rdiffweb Web
7.5
HIGH
EPSS
0.2%
2022 CWE-614 1 PoC

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2.

CVE-2022-35923
v8n Web
7.5
HIGH
EPSS
0.4%
2022 CWE-400 1 PoC

v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service attack. In testing of the `lowercase()` function a payload of 'a' + 'a'.repeat(i) + 'A' with 32 leading characters took 29443 ms to execute. The same issue happens with uppercase(). Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-41840
Welcart e-Commerce (WordPress plugin) Web Windows ⚡ nuclei
7.5
HIGH
EPSS
79.4%
2022 CWE-22 0 PoCs

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

CVE-2022-43551
https://github.com/curl/curl Web
7.5
HIGH
EPSS
0.0%
2022 CWE-319 1 PoC

A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request, it does not detect the HS

CVE-2022-37301
Modicon M340 CPU (part numbers BMXP34*) General
7.5
HIGH
EPSS
0.5%
2022 CWE-191 1 PoC

A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)

CVE-2022-45925
Software Genérico Web
7.5
HIGH
EPSS
1.7%
2022 3 PoCs

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.

CVE-2022-21716
twisted Networking
7.5
HIGH
EPSS
1.2%
2022 CWE-120 1 PoC

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.

CVE-2022-26303
OAS Platform General
7.5
HIGH
EPSS
0.3%
2022 CWE-306 1 PoC

An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-1721
jgraph/drawio General
7.5
HIGH
EPSS
1.2%
2022 CWE-22 1 PoC

Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application.

CVE-2022-23457
org.owasp.esapi:esapi Web
7.5
HIGH
EPSS
0.6%
2022 CWE-22 2 PoCs

ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the 'input' path. This vulnerability is patched in release 2.3.0.0 of ESAPI. As a workaround, it is possible to write one's own implementation of the Va

CVE-2022-44216
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.

CVE-2022-2192
HYPR Server General
7.5
HIGH
EPSS
0.7%
2022 CWE-425 1 PoC

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

CVE-2022-21266
Communications Billing and Revenue Management Web Database
7.5
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Confidenti

CVE-2022-1713
jgraph/drawio General ⚡ nuclei
7.5
HIGH
EPSS
90.2%
2022 CWE-918 1 PoC

SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

CVE-2022-24190
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a POST request to accept their own bind request, without the end-users approval or interaction.