2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-43140
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
40.0%
2022 0 PoCs

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.

CVE-2022-25837
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code pairing if the MITM negotiates BR/EDR Secure Simple Pairing in Secure Connections mode using the Passkey association model with the pairing Initiator and BR/EDR Legacy PIN code pairing with the pairing Responder and brute forces the Passkey entered by the user into the Responder as a 6-digit PIN code. The MITM attacker c

CVE-2022-25026
Software Genérico Web
7.5
HIGH
EPSS
2.9%
2022 1 PoC

A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.

CVE-2022-24785
moment Web
7.5
HIGH
EPSS
2.3%
2022 CWE-22 1 PoC

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVE-2022-25867
io.socket:socket.io-client General
7.5
HIGH
EPSS
0.9%
2022 1 PoC

The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.

CVE-2022-35290
SAP Authenticator for Android General
7.5
HIGH
EPSS
0.3%
2022 CWE-200 2 PoCs

Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

CVE-2022-41404
Software Genérico General
7.5
HIGH
EPSS
0.8%
2022 2 PoCs

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVE-2022-44356
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
47.1%
2022 0 PoCs

WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.

CVE-2022-1176
livehelperchat/livehelperchat General
7.5
HIGH
EPSS
0.3%
2022 CWE-843 1 PoC

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

CVE-2022-27674
AMD μProf Windows
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.

CVE-2022-21159
libiec61850 General
7.5
HIGH
EPSS
0.4%
2022 CWE-835 2 PoCs

A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence of malformed iec61850 messages to trigger this vulnerability.

CVE-2022-42060
Software Genérico Networking
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-1784
jgraph/drawio General
7.5
HIGH
EPSS
0.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.

CVE-2022-21227
sqlite3 Database
7.5
HIGH
EPSS
0.3%
2022 2 PoCs

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVE-2022-40898
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVE-2022-47076
Software Genérico General
7.5
HIGH
EPSS
23.4%
2022 3 PoCs

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.

CVE-2022-3780
Remote Desktop Manager Database
7.5
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions.

CVE-2022-22781
Zoom Client for Meetings for MacOS (Standard and for IT Admin) General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

CVE-2022-3754
thorsten/phpmyfaq Web
7.5
HIGH
EPSS
0.9%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE-2022-23831
AMD μProf Windows
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.