2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21129
nemo-appium General
7.4
HIGH
EPSS
1.1%
2022 CWE-78 1 PoC

Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.

CVE-2022-20866
Cisco Adaptive Security Appliance (ASA) Software Networking
7.4
HIGH
EPSS
8.9%
2022 CWE-203 1 PoC

A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. An attacker could exploit this vulnerability by using a Lenstra side-channel attack against the targeted device. A successful exploit could allow the attacker to retrieve the RSA private key. The following condit

CVE-2022-25923
exec-local-bin General
7.4
HIGH
EPSS
1.6%
2022 CWE-78 1 PoC

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

CVE-2022-25926
window-control General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

CVE-2022-25962
vagrant.js General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

CVE-2022-29217
pyjwt General
7.4
HIGH
EPSS
0.4%
2022 CWE-327 1 PoC

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always

CVE-2022-0432
mastodon/mastodon General ⚡ nuclei
7.4
HIGH
EPSS
57.1%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

CVE-2022-1253
strukturag/libde265 General
7.4
HIGH
EPSS
0.5%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

CVE-2022-21542
JD Edwards EnterpriseOne Tools Web Database
7.4
HIGH
EPSS
0.4%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as we

CVE-2022-1467
AVEVA InTouch Access Anywhere Windows
7.4
HIGH
EPSS
0.3%
2022 CWE-668 1 PoC

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVE-2022-25890
wifey General
7.4
HIGH
EPSS
1.5%
2022 CWE-78 1 PoC

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

CVE-2022-25171
p4 General
7.4
HIGH
EPSS
1.9%
2022 1 PoC

The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

CVE-2022-1809
radareorg/radare2 General
7.4
HIGH
EPSS
0.3%
2022 CWE-824 1 PoC

Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2022-25916
mt7688-wiscan General
7.4
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

CVE-2022-25350
puppet-facter General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

CVE-2022-23632
traefik Web Networking
7.4
HIGH
EPSS
0.6%
2022 CWE-295 1 PoC

Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a wrong TLS configuration. When sending a request using FQDN handled by a router configured with a dedicated TLS configuration, the TLS configuration falls back to the default configuration that might not correspond to the configured one. If the CNAME flattening is enabled, the sel

CVE-2022-24377
cycle-import-check General
7.4
HIGH
EPSS
1.4%
2022 1 PoC

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

CVE-2022-25855
create-choo-app3 General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-26073
Eufy Homebase 2 General
7.4
HIGH
EPSS
0.1%
2022 CWE-190 1 PoC

A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.