2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-41999
OpenImageIO General
7.5
HIGH
EPSS
0.3%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-43326
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.

CVE-2022-50978
VibroLine VLX1 HD 5.0 General
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

CVE-2022-4244
RHINT Camel-K-1.10.1 General
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

CVE-2022-35737
Software Genérico Web Database
7.5
HIGH
EPSS
51.9%
2022 3 PoCs

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

CVE-2022-23990
Software Genérico General
7.5
HIGH
EPSS
3.7%
2022 3 PoCs

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVE-2022-48482
Software Genérico Windows
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

CVE-2022-21167
Masuit.Tools.Core General
7.5
HIGH
EPSS
0.9%
2022 1 PoC

All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

CVE-2022-47116
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.

CVE-2022-21231
deep-get-set Web
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)

CVE-2022-43945
linux_kernel General
7.5
HIGH
EPSS
0.2%
2022 CWE-131 3 PoCs

The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by sending an RPC message over TCP with garbage data added at the end of the message. The RPC message with garbage data is still correctly formed according to the specification and is passed forward to handlers. Vulnerable code in NFSD is not expecting the oversized request and writes

CVE-2022-45640
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

CVE-2022-40303
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 5 PoCs

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.

CVE-2022-34393
BIOS General
7.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-24897
xwiki-commons Web
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations on the filesystem. Writing an attacking script in Velocity requires the Script rights in XWiki so not all users can use it, and it also requires finding an XWiki API which returns a File. The problem has been patched in versions 12.6.7, 12.10.3, and 13.0. There is no easy workaround for fixing this vulnerability other th

CVE-2022-45129
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.

CVE-2022-46076
Software Genérico Web
7.5
HIGH
EPSS
1.3%
2022 1 PoC

D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.

CVE-2022-25304
opcua General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-21622
SOA Suite Web Database
7.5
HIGH
EPSS
1.3%
2022 1 PoC

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2022-36319
Firefox ESR General
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.