2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1941
protobuf-cpp General
7.5
HIGH
EPSS
0.2%
2022 CWE-1286 1 PoC

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.

CVE-2022-24839
nekohtml Web
7.5
HIGH
EPSS
0.5%
2022 CWE-400 1 PoC

org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability.

CVE-2022-42953
Software Genérico General
7.5
HIGH
EPSS
10.9%
2022 2 PoCs

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

CVE-2022-25891
github.com/containrrr/shoutrrr/pkg/util General
7.5
HIGH
EPSS
0.6%
2022 1 PoC

The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.

CVE-2022-44156
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.

CVE-2022-21208
node-opcua General
7.5
HIGH
EPSS
1.1%
2022 1 PoC

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-25932
InRouter302 Networking
7.4
HIGH
EPSS
0.5%
2022 CWE-284 1 PoC

The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.

CVE-2022-37193
Software Genérico General
7.4
HIGH
EPSS
0.3%
2022 1 PoC

Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials.

CVE-2022-24431
abacus-ext-cmdline General
7.4
HIGH
EPSS
1.9%
2022 1 PoC

All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.

CVE-2022-26092
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

CVE-2022-0602
tastyigniter/tastyigniter Web
7.4
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0.

CVE-2022-0159
orchardcms/orchardcore Web
7.4
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-21810
smartctl General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.

CVE-2022-24707
timetracker Web Database
7.4
HIGH
EPSS
2.4%
2022 CWE-89 2 PoCs

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642. This was happening because the Puncher plugin was reusing code from other places and was relying on an unsanitized date parameter in POST requests. Because the parameter was not checked, it was possible to craft POST requests with malicious SQL for Time Tracker database. This issue has been resolved in in version 1.20.0.5642. Users unable to upgra

CVE-2022-0243
orchardcms/orchardcore Web
7.4
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

CVE-2022-21182
InRouter302 Web Networking
7.4
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-47630
Software Genérico General
7.4
HIGH
EPSS
0.6%
2022 1 PoC

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

CVE-2022-25908
create-choo-electron General
7.4
HIGH
EPSS
1.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-21191
global-modules-path General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

CVE-2022-25906
is-http2 Web
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.