2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22774
TIBCO Managed File Transfer Command Center General
8.6
HIGH
EPSS
0.7%
2022 1 PoC

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.

CVE-2022-50909
Algo 8028 General
8.6
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.

CVE-2022-50907
e107 CMS Web
8.6
HIGH
EPSS
0.5%
2022 CWE-434 1 PoC

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.

CVE-2022-4814
usememos/memos General
8.6
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-42843
tvOS General
8.6
HIGH
EPSS
0.1%
2022 4 PoCs

This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.

CVE-2022-50922
Audio Conversion Wizard General
8.6
HIGH
EPSS
0.3%
2022 CWE-120 1 PoC

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.

CVE-2022-33719
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.2%
2022 CWE-20 1 PoC

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

CVE-2022-0768
rudloff/alltube General
8.6
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

CVE-2022-23923
jailed General
8.6
HIGH
EPSS
0.1%
2022 2 PoCs

All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.

CVE-2022-4800
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-940 1 PoC

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-21801
Software Genérico General
8.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to a reboot. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-4799
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4813
usememos/memos General
8.6
HIGH
EPSS
0.3%
2022 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4848
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-940 1 PoC

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1055
Kernel General
8.6
HIGH
EPSS
0.0%
2022 CWE-416 2 PoCs

A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5

CVE-2022-3805
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress Web Windows ⚡ nuclei
8.6
HIGH
EPSS
8.5%
2022 CWE-639 0 PoCs

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

CVE-2022-31188
cvat General
8.6
HIGH
EPSS
35.7%
2022 CWE-918 2 PoCs

CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-4686
usememos/memos General
8.6
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-43939
🔥 KEV Pentaho Business Analytics Server General ⚡ nuclei
8.6
HIGH
EPSS
93.3%
2022 CWE-647 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CVE-2022-50806
4images Web
8.6
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.