2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2591
FLEX-1085 General
7.5
HIGH
EPSS
3.8%
2022 CWE-404 1 PoC

A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-1579
Login Block IPs General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

CVE-2022-25882
onnx General
7.5
HIGH
EPSS
5.8%
2022 CWE-22 1 PoC

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

CVE-2022-31474
BackupBuddy General ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2022 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

CVE-2022-45269
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
27.4%
2022 0 PoCs

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

CVE-2022-37620
Software Genérico General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.

CVE-2022-25324
bignum General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.

CVE-2022-0203
crater-invoice/crater General
7.5
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

CVE-2022-3602
OpenSSL General
7.5
HIGH
EPSS
83.5%
2022 7 PoCs

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms impl

CVE-2022-30746
Smart Things Web
7.5
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

CVE-2022-22143
convict Web
7.5
HIGH
EPSS
1.7%
2022 2 PoCs

The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)

CVE-2022-46432
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

An exploitable firmware modification vulnerability was discovered on TP-Link TL-WR743ND V1. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v3.12.20 and earlier.

CVE-2022-20347
Android General
7.5
HIGH
EPSS
0.7%
2022 2 PoCs

In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228450811

CVE-2022-24298
FreeOpcUa/freeopcua General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-40874
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.

CVE-2022-32574
iota All-In-One Security Kit Web
7.5
HIGH
EPSS
1.4%
2022 CWE-415 1 PoC

A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-3382
HIWIN Robot System Software General
7.5
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the controller and cause a denial-of-service condition.

CVE-2022-42734
syngo Dynamics General
7.5
HIGH
EPSS
0.2%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.

CVE-2022-47522
Software Genérico General
7.5
HIGH
EPSS
15.7%
2022 1 PoC

The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.

CVE-2022-39801
SAP GRC Access Control Emergency Access Management Networking
7.5
HIGH
EPSS
0.4%
2022 CWE-287 1 PoC

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.